Defending against flooding-based distributed denial-of-service attacks: A tutorial

被引:255
作者
Chang, RKC [1 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
关键词
D O I
10.1109/MCOM.2002.1039856
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Flooding-based distributed denial-of-service (DDoS) attack presents a very serious threat to the stability of the Internet. In a typical DDoS attack, a large number of compromised hosts are amassed to send useless packets to jam a victim, or its Internet connection, or both. In the last two years, it is discovered that DDoS attack methods and tools are becoming more sophisticated, effective, and also more difficult to trace to the real attackers. On the defense side, current technologies are still unable to withstand large-scale attacks. The main purpose of this article is therefore twofold. The first one is to describe various DDoS attack methods, and to present a systematic review and evaluation of the existing defense mechanisms. The second is to discuss a longer-term solution, dubbed the Internet-firewall approach, that attempts to intercept attack packets in the Internet core, well before reaching the victim.
引用
收藏
页码:42 / 51
页数:10
相关论文
共 15 条
[1]  
[Anonymous], 2001, ACM
[2]  
*COM EM RESP TEAM, 1999, DISTR SYST INTR TOOL
[3]  
*COMP EN RESP TEAM, 2000, IN200004 COMP EN RES
[4]   Quickest detection for sequential decentralized decision systems [J].
Crow, RW ;
Schwartz, SC .
IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1996, 32 (01) :267-283
[5]  
Dittrich David., 1999, The DoS project's 'trinoo'distributed denial of service attack tool
[6]  
Ferguson Paul, 2000, Network Ingress Filtering: Defeating Denial of Service Attacks Which Employ IP Source Address Spoofing, DOI [10.17487/rfc2827, 10.17487/RFC2827]
[7]  
Gibson S., 2002, STRANGE TALE DENIAL
[8]  
Gibson S, 2002, DISTRIBUTED REFLECTI
[9]  
Moore D., 2001, P 10 USENIX SEC S
[10]  
PARK K, 2001, P ACM SIGCOMM, P15