A Service-oriented DDoS detection mechanism using pseudo state in a flow router

作者:Park PyungKoo*; Yoo SeongMin; Ryu HoYong; Park Jaehyung; Kim Cheol Hong; Choi Su il; Ryou JaeCheol
来源:Multimedia Tools and Applications, 2015, 74(16): 6341-6363.
DOI:10.1007/s11042-014-2100-5

摘要

As distributed denial-of-service (DDoS) attacks have caused serious economic and social problems, there have been numerous researches to defend against them. The current DDoS defense system relies on a dedicated security device, which is located in front of the server it is required to protect. To detect DDoS attacks, this security device compares incoming traffic to known attack patterns. Since such a defense mechanism cannot prevent an influx of attack traffic into the network, and every packet must be compared against the known attack patterns, the mechanism often degrades the service. In this paper, we propose the Service-oriented DDoS Detection Mechanism using a Pseudo State (SDM-P), which runs on network devices to defend against DDoS attacks without sacrificing performance in terms of data forwarding. The SDM-P mechanism is suitable for both low- and high-rate attacks. In addition, we verified the performance of the SDM-P mechanism by evaluating its performance using a DDoS attack similar to the one that occurred in Korea and the USA on July 7th, 2009.

  • 出版日期2015-8

全文