Network domain entrypoint/path determination for DDoS attacks
File(s)NOMS_Final_Version.pdf (279.5 KB)
Accepted version
Author(s)
Thing, VLL
Sloman, M
Dulay, N
Type
Conference Paper
Abstract
A method to determine entry points and paths of DDoS attack traffic flows into network domains is proposed. We determine valid source addresses seen by routers from sampled traffic under non-attack conditions. Under attack conditions, we detect route anomalies by determining which routers have been used for unknown source addresses to construct the attack paths. We show results from simulations to detect the routers carrying attack traffic in the victim's network domain. Our approach is non-intrusive, not requiring any changes to the Internet routers and data packets. Precise information regarding the attack is not required allowing a wide variety of DDoS attack detection techniques to be used. The victim is also relieved from the traceback task during an attack. Our algorithm is simple and efficient, allowing for a fast traceback and the method is scalable due to the distribution of processing workload.
Version
Accepted version
Date Issued
2008
Citation
2008, pp.57-64
ISBN
978-1-4244-2065-0
Publisher
IEEE SERVICE CENTER, 445 HOES LANE, PO BOX 1331, PISCATAWAY, NJ 08855-1331 USA
Source Title
IEEE Network Operations and Management Symposium
Start Page
57
End Page
64
Copyright Statement
Copyright © 2008 reprinted from The Institute of Electrical and Electronics Engineers, Inc.
This material is posted here with permission of the IEEE. Such permission
of the IEEE does not in any way imply IEEE endorsement of any of Imperial
College, London's products or services. Internal or personal use of this
material is permitted. However, permission to reprint/republish this
material for advertising or promotional purposes or for creating new
collective works for resale or redistribution must be obtained from the
IEEE by writing to pubs-permissions@ieee.org.
By choosing to view this document, you agree to all provisions of the
copyright laws protecting it.
This material is posted here with permission of the IEEE. Such permission
of the IEEE does not in any way imply IEEE endorsement of any of Imperial
College, London's products or services. Internal or personal use of this
material is permitted. However, permission to reprint/republish this
material for advertising or promotional purposes or for creating new
collective works for resale or redistribution must be obtained from the
IEEE by writing to pubs-permissions@ieee.org.
By choosing to view this document, you agree to all provisions of the
copyright laws protecting it.
Identifier
http://icsd.i2r.a-star.edu.sg/staff/vriz/Publications/NOMS2008_Network_Domain_Points.pdf
Source
IEEE Network Operations and Management Symposium
Source Place
Salvador, BRAZIL
Coverage Spatial
Salvador, Bahia