Path Attestation Scheme to Avert DDoS Flood Attacks - NETWORKING 2010
Conference Papers Year : 2010

Path Attestation Scheme to Avert DDoS Flood Attacks

Abstract

DDoS mitigation schemes are increasingly becoming relevant in the Internet. The main hurdle faced by such schemes is the \nearly indistinguishable" line between malicious tra c and genuine tra c. It is best tackled with a paradigm shift in connection handling by attest- ing the path. We therefore propose the scheme called \Path Attestation Scheme" coupled with a metric called \Con dence Index" to tackle the problem of distinguishing malicious and genuine tra c in a progressive manner, with varying levels of certainty. We support our work through an experimental study to establish the stability of Internet topology by using 134 di erent global Internet paths over a period of 16 days. Our Path Attestation Scheme was able to successfully distinguish between malicious and genuine tra c, 85% of the time. The scheme presupposes support from a fraction of routers in the path.
Fichier principal
Vignette du fichier
main.pdf (379.03 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01059127 , version 1 (29-08-2014)

Licence

Identifiers

Cite

Raktim Bhattacharjee, S. Sanand, S. V. Raghavan. Path Attestation Scheme to Avert DDoS Flood Attacks. 9th International IFIP TC 6 Networking Conference (NETWORKING), May 2010, Chennai, India. pp.397-408, ⟨10.1007/978-3-642-12963-6_32⟩. ⟨hal-01059127⟩
89 View
135 Download

Altmetric

Share

More