Header menu link for other important links
X
Path attestation scheme to avert DDoS flood attacks
Raktim Bhattacharjee, S. Sanand, Serugudi V. Raghavan
Published in
2010
Volume: 6091 LNCS
   
Pages: 397 - 408
Abstract
DDoS mitigation schemes are increasingly becoming relevant in the Internet. The main hurdle faced by such schemes is the "nearly indistinguishable" line between malicious traffic and genuine traffic. It is best tackled with a paradigm shift in connection handling by attesting the path. We therefore propose the scheme called "Path Attestation Scheme" coupled with a metric called "Confidence Index" to tackle the problem of distinguishing malicious and genuine traffic in a progressive manner, with varying levels of certainty. We support our work through an experimental study to establish the stability of Internet topology by using 134 different global Internet paths over a period of 16 days. Our Path Attestation Scheme was able to successfully distinguish between malicious and genuine traffic, 85% of the time. The scheme presupposes support from a fraction of routers in the path. © 2010 Springer-Verlag.
About the journal
JournalLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
ISSN03029743
Open AccessYes
Concepts (17)
  •  related image
    CASCADED FILTERS
  •  related image
    CONFIDENCE INDICES
  •  related image
    Experimental studies
  •  related image
    GLOBAL INTERNET
  •  related image
    Internet topologies
  •  related image
    MALICIOUS TRAFFIC
  •  related image
    MITIGATION SCHEMES
  •  related image
    Paradigm shifts
  •  related image
    CASCADED FILTERS
  •  related image
    CONFIDENCE INDICES
  •  related image
    DDOS MITIGATIONS
  •  related image
    GLOBAL INTERNET
  •  related image
    MALICIOUS TRAFFIC
  •  related image
    UNSPOOFABLE IDENTITY
  •  related image
    Internet
  •  related image
    Artificial intelligence
  •  related image
    Computers