Abstract
High-rate flooding attacks (aka Distributed Denial of Service or DDoS attacks) continue to constitute a pernicious threat within the Internet domain. In this work we demonstrate how using packet source IP addresses coupled with a change-point analysis of the rate of arrival of new IP addresses may be sufficient to detect the onset of a high-rate flooding attack. Importantly, minimizing the number of features to be examined, directly addresses the issue of scalability of the detection process to higher network speeds. Using a proof of concept implementation we have shown how pre-onset IP addresses can be efficiently represented using a bit vector and used to modify a "white list" filter in a firewall as part of the mitigation strategy. © IFIP International Federation for Information Processing 2010.
Author supplied keywords
Cite
CITATION STYLE
Ahmed, E., Mohay, G., Tickle, A., & Bhatia, S. (2010). Use of IP addresses for high rate flooding attack detection. In IFIP Advances in Information and Communication Technology (Vol. 330, pp. 124–135). Springer New York LLC. https://doi.org/10.1007/978-3-642-15257-3_12
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.