A novel rate limit algorithm against meek DDoS attacks

  • Authors:
  • Yinan Jing;Xueping Wang;Xiaochun Xiao;Gendu Zhang

  • Affiliations:
  • School of Information Science & Engineering, Fudan University, Shanghai, China;School of Information Science & Engineering, Fudan University, Shanghai, China;School of Information Science & Engineering, Fudan University, Shanghai, China;School of Information Science & Engineering, Fudan University, Shanghai, China

  • Venue:
  • ATC'06 Proceedings of the Third international conference on Autonomic and Trusted Computing
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Distributed denial-of-service attack is one of major threats to Internet today. Rate limit algorithm with max-min fairness is an effective countermeasure to defeat flooding-style DDoS attacks under the assumption that attackers are more aggressive than legitimate users. However, under a “meek” DDoS attack where such an assumption is no longer valid, it will fail to protect legitimate traffic effectively. In order to improve the survival ratio of legitimate packets, an IP traceback based rate limit algorithm is proposed. Simulation results show that it could not only mitigate the DDoS attack effect, but also improve the throughput of legitimate traffic even under a meek attack.