10th IEEE International Conference on Network Protocols (ICNP'02) Attacking DDoS at the Source Paris, France November 12-November 15 ISBN: 0-7695-1856-7
Distributed denial-of-service (DDoS) attacks present an Internet-wide threat. We propose D-WARD, a DDoS defense system deployed at source-end networks that autonomously detects and stops attacks originating from these networks. Attacks are detected by the constant monitoring of two-way traffic flows between the network and the rest of the Internet and periodic comparison with normal flow models. Mismatching flows are rate-limited in proportion to their aggressiveness. D-WARD offers good service to legitimate traffic even during an attack, while effectively reducing DDoS traffic to a negligible level. A prototype of the system has been built in a Linux router. We show its effectiveness in various attack scenarios, discuss motivations for deployment, and describe associated costs.
Citation:
Jelena Mirković, Gregory Prier, Peter Reiher, "Attacking DDoS at the Source," icnp, pp.312, 10th IEEE International Conference on Network Protocols (ICNP'02), 2002 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||