A New DDoS Defense Method

作者:Wang Dongqi; Lin Luo; Chang Guiran
来源:International Symposium on Intelligent Information Systems and Applications, 2009-10-28 to 2009-10-30.

摘要

Large scale DDoS aims to take victim down by sending large traffic. Existing work in DDoS defense tries to filter attack traffic. The filtering process causes collateral damage. A lot of researches had been done to mitigate collateral damages, such as IP traceback, finding new DDoS recognizing method, and so on. All these researches confirm attack traffic, filter it, nothing will be done after filtering. In this paper we proposed a new DDoS defense method which uses an improved nest loop algorithm to handle filtered traffic, after that, access control lists are established to reduce collateral damage. A careful experiment evaluation shows that our method can be used to defend against large scale DDoS, and it gives a new way to mitigate collateral damage.