loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Second International Workshop on Security in Distributed Computing Systems (SDCS) (ICDCSW'05)
Real-Time Protection against DDoS Attacks Using Active Gateways
Columbus, Ohio, USA
June 06-June 10
ISBN: 0-7695-2328-5
Onur Demir, State University of New York at Binghamton
Kanad Ghose, State University of New York at Binghamton
This paper presents solutions for protecting servers against Distributed Denial-of-Service (DDoS) attacks that inundate the system with file download and script execution requests. Our solution uses a dynamic packet filtering on dual-ported active NIC based gateways to drop attacking packets based on locally measured request rates and information from the server (such as server loading, number of incomplete connections). A variety of techniques for performing such packet filtering in real-time are discussed. A prototype implementation using a testbed of several clients, attacking machines and servers indicates that considerable improvements in the response times to legitimate requests and overall improvements in the performance of the servers are realized by the proposed scheme. As a sustained high-volume attack is started, the intelligent gateway is successful in detecting and filtering out apparently malicious traffic in only a few 10s of seconds.
Citation:
Onur Demir, Kanad Ghose, "Real-Time Protection against DDoS Attacks Using Active Gateways," icdcsw, vol. 2, pp.224-231, Second International Workshop on Security in Distributed Computing Systems (SDCS) (ICDCSW'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.