A taxonomy of DDoS attack and DDoS Defense mechanisms

被引:1188
作者
Mirkovic, J
Reiher, P
机构
[1] Univ Delaware, Comp & Informat Sci Dept, Newark, DE 19716 USA
[2] Univ Calif Los Angeles, Dept Comp Sci, Los Angeles, CA 90095 USA
关键词
D O I
10.1145/997150.997156
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 [计算机科学与技术];
摘要
Distributed denial-of-service (DDoS) is a rapidly growing problem. The multitude and variety of both the attacks and the defense approaches is overwhelming. This paper presents two taxonomies for classifying attacks and defenses, and thus provides researchers with a better understanding of the problem and the current solution space. The attack classification criteria was selected to highlight commonalities and important features of attack strategies, that define challenges and dictate the design of countermeasures. The defense taxonomy classifies the body of existing DDoS defenses based on their design decisions; it then shows how these decisions dictate the advantages and deficiencies of proposed solutions.
引用
收藏
页码:39 / 53
页数:15
相关论文
共 74 条
[1]
ANDERSEN DG, 2001, P HOTN 2 NOV
[2]
ANDERSEN DG, 2003, P 4 US S INT TECHN S
[3]
[Anonymous], 2000, IETF
[4]
[Anonymous], SNORT OPEN SOURCE NE
[5]
*ARB NETW, PEAKFL PLATF
[6]
Aura T., 2001, LECT NOTES COMPUTER, V2133
[7]
AXELSSON S, 9915 CHALM U DEP COM
[8]
BARFORD P, 2002, P 2 ACM SIGCOMM INT
[9]
*BBN TECHN, INTR TOL UNPR AD
[10]
*BBN TECHN, APPL PART THEIR OWN