TY - JOUR
T1 - Active countermeasure platform against DDoS attacks
AU - Kashiwa, Dai
AU - Chen, Eric Y.
AU - Fuji, Hitoshi
AU - Machida, Shuichi
AU - Shigeno, Hiroshi
AU - Okada, Ken Ichi
AU - Matsushita, Yutaka
PY - 2002/12
Y1 - 2002/12
N2 - Distributed Denial of Service (DDoS) attacks are a pressing problem on the Internet as demonstrated by recent attacks on major e-commerce servers and ISPs. Since the attack is highly distributed, an effective solution must be formulated with a distributed approach. Recently, some solutions, in which intermediate network nodes filter or shape congested traffic, have been proposed. These solutions may decrease the congested traffic, but they still cause "collateral victims problem." that is, legitimate packets may be discarded mistakenly. In this paper, we propose Active Countermeasure Platform to minimize traffic congestion and to address the collateral victim problem using the Active Networks paradigm, which incorporates programmability into intermediate network nodes. Our platform can prevent overloading of the target and consuming the network bandwidth of both the backbone and the protected site autonomously. In addition, it can improve the collateral victim problem based on user policy. This paper shows the concept of our platform, system design and evaluation of the effectiveness using a prototype.
AB - Distributed Denial of Service (DDoS) attacks are a pressing problem on the Internet as demonstrated by recent attacks on major e-commerce servers and ISPs. Since the attack is highly distributed, an effective solution must be formulated with a distributed approach. Recently, some solutions, in which intermediate network nodes filter or shape congested traffic, have been proposed. These solutions may decrease the congested traffic, but they still cause "collateral victims problem." that is, legitimate packets may be discarded mistakenly. In this paper, we propose Active Countermeasure Platform to minimize traffic congestion and to address the collateral victim problem using the Active Networks paradigm, which incorporates programmability into intermediate network nodes. Our platform can prevent overloading of the target and consuming the network bandwidth of both the backbone and the protected site autonomously. In addition, it can improve the collateral victim problem based on user policy. This paper shows the concept of our platform, system design and evaluation of the effectiveness using a prototype.
KW - Active networks
KW - DDoS attack
KW - Network architecture
KW - Policy-based shaping
KW - Traffic shaping
UR - http://www.scopus.com/inward/record.url?scp=0037002097&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=0037002097&partnerID=8YFLogxK
M3 - Article
AN - SCOPUS:0037002097
SN - 0916-8532
VL - E85-D
SP - 1918
EP - 1928
JO - IEICE Transactions on Information and Systems
JF - IEICE Transactions on Information and Systems
IS - 12
ER -