Conference Proceedings
Defending against distributed denial of service attacks using selective pushback
T Peng, C Leckie, K Ramamohanarao
Proceeding of the International Conference on Telecommunications | Published : 2002
Abstract
In this paper, we introduce a router-based system to defend against Distributed Denial of Service (DDoS) attacks. DDoS attacks are treated as a congestion-control problem. The main issue is to identify the congestion and then pushback a packet filter to the router closest to the source that causes congestion. Unlike previous approaches, we propose an anomaly detection scheme using source information. Since the source IP address is not trustable, we obtain source information by probabilistic packet marking. By filtering the packet via source information, we can filter the malicious traffic while protecting the legitimate traffic.