Traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination

Kei Sakuma, Hiromu Asahina, Shuichiro Haruta, Iwao Sasase

研究成果: Conference contribution

7 被引用数 (Scopus)

抄録

Recently, the detection of target link flooding attack which is a new type of DDoS (Distributed Denial of Service) is required. Target link flooding attack is used for disconnecting a specific area from the Internet. It is more difficult to detect and mitigate this attack than legacy DDoS since attacking flows do not reach the target region. Among several schemes for target link flooding attack, the scheme focusing on traceroute is gathering attention. The idea behind that is the attacker needs to send traceroute to investigate the topology around targeted region before attack starts. That scheme detects the attack by finding rapid increase of traceroute. However, it cannot work when attacker's traceroute ratio is low. In this paper, we propose traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination. Since the attacker must choose the link flooded to disconnect the target area, the destinations of attacker's traceroutes are concentrated within several hops from the target link while legitimate user's ones are distributed uniformly. By analyzing the number of traceroutes as per hop counts, the change can be emphasized and the attack symptom might be more easily captured. By computer simulations, we first prove the above hypotheses and show that our scheme has more robustness compared with the conventional scheme.

本文言語English
ホスト出版物のタイトル2017 23rd Asia-Pacific Conference on Communications
ホスト出版物のサブタイトルBridging the Metropolitan and the Remote, APCC 2017
出版社Institute of Electrical and Electronics Engineers Inc.
ページ1-6
ページ数6
ISBN(電子版)9781740523905
DOI
出版ステータスPublished - 2018 2月 27
イベント23rd Asia-Pacific Conference on Communications, APCC 2017 - Perth, Australia
継続期間: 2017 12月 112017 12月 13

出版物シリーズ

名前2017 23rd Asia-Pacific Conference on Communications: Bridging the Metropolitan and the Remote, APCC 2017
2018-January

Other

Other23rd Asia-Pacific Conference on Communications, APCC 2017
国/地域Australia
CityPerth
Period17/12/1117/12/13

ASJC Scopus subject areas

  • コンピュータ ネットワークおよび通信
  • 信号処理

フィンガープリント

「Traceroute-based target link flooding attack detection scheme by analyzing hop count to the destination」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル