Defeating Denial-of-Service Attacks on the Internet

  • Authors:
  • Baoqing Ye

  • Affiliations:
  • -

  • Venue:
  • ICICS '01 Proceedings of the Third International Conference on Information and Communications Security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network Denial-of-Service (N-DoS) attacks are one of the fastest growing types of attack on the Internet. This paper addresses the vulnerabilities in Internet protocols, as well as deficiencies in flow-control in the Internet, both of which contribute to the loss of resource availability when networks suffer N-DoS attacks. Furthermore, an AFFC (Anti-flooding Flow-Control) model is presented to defend against flooding N-DoS attacks. AFFC policies regulate unresponsive elastic traffic and aggressive best-effort traffic for specific flow classes. Experiments have demonstrated that the deployment of this model can thwart harmful flows and prevent congestion collapse by flooding N-DoS attacks.