Logo image
A Tag-based Overlay Architecture for Real Time IP Traceback and Defending Against DDoS Attack Near Source
Thesis

A Tag-based Overlay Architecture for Real Time IP Traceback and Defending Against DDoS Attack Near Source

蔡維倫
Masters, 國立清華大學, 資訊系統與應用研究所
2006

Abstract

分散式阻斷服務攻擊 以標籤為基礎之疊加網路 封包註記 DDoS Tag-Based Overlay Networks Spoofing Attack, Packet Marking
DDoS attack has become a serious security problem in the Internet nowadays. When DDoS attack starts, all of the bandwidth or resources of the victim will be occupied by the useless packets and the attack traffic will deny services of the victim. A single point defense near the victim side is not effective in dealing with the enormous and distributed attack traffic. In this paper, we propose a tag-based overlay architecture for real time IP traceback and defending against DDoS attacks with spoofing source address, large scale, and highly distributed features. The tag-based overlay architecture is a two-layer overlay defense network consists of several local overlay defense networks and one global overlay defense network to be the framework of real time IP traceback. To characterize the DDoS attack flows, each packet that passes through an edge router to the Internet will be associated with a packet tag by the edge router. The packet tag is a kind of deterministic packet marking and is used to characterize the packet flows of edge routers. The defending against DDoS attack consists of two stages. In the first stage, a victim sends out the AT signature to all edge routers via the overlay network and edge routers block all traffic (attack and good) if the packet tag generated by it is in the AT signature. In the second stage, a victim sends out the AT&IP signature to all edge routers via the overlay network and edge routers block those packets whose packet tag and IP address match those in the AT&IP signature. We simulate and verify the proposed approach using GTNetS network simulator. The simulation results demonstrate that our approach can effectively block attack traffic and protect legitimate traffic when all edge routers are all participated in the overlay network.

Metrics

1 Record Views

Details

Logo image