Layer 3, 4 and 7 DDoS attacks are common and very difficult to defend against. The academic community has published hundreds of well thought out algorithms, which require changes in computer networking equipment, to better detect and mitigate these attacks. The problem with these solutions, is that they require computer networking manufacturers to make changes to their hardware and/or software. On the other hand, with our solution, absolutely no hardware or software changes are required. We only require the use of BGP4 Flow-Spec, which has already been widely deployed many years ago. Further the customers’ own ISP does not require Flow-Spec. Our algorithm protects groups of over sixtyfive thousand different customers, via the aggregation into one very small Flow-Spec rule. In this paper, we propose our novel, low cost and efficient solution, to both detect and greatly mitigate any and all types of L347 DDoS Web attacks.
CITATION STYLE
Booth, T., & Andersson, K. (2016). Network DDoS layer 3/4/7 mitigation via dynamic web redirection. In Communications in Computer and Information Science (Vol. 670, pp. 111–125). Springer Verlag. https://doi.org/10.1007/978-3-319-48021-3_8
Mendeley helps you to discover research relevant for your work.