Defending Against Low-Rate TCP Attacks: Dynamic Detection and Protection

  • Authors:
  • Haibin Sun;John C. S. Lui;David K. Y. Yau

  • Affiliations:
  • The Chinese University of Hong Kong;The Chinese University of Hong Kong;Purdue University

  • Venue:
  • ICNP '04 Proceedings of the 12th IEEE International Conference on Network Protocols
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

We consider a distributed approach to detect and to defend against the low-rate TCP attack. The low-rate TCP attack is essentially a periodic short burst which exploits the homogeneity of the minimum retransmission timeout (RTO) of TCP flows and forces all affected TCP flows to back off and enter the retransmission timeout state. This sort of attack is difficult to identify due to a large family of attack patterns. We propose a distributed detection mechanism which uses the dynamic time warping method to robustly and accurately identify the existence of this sort of attack. Once the attack is detected, a fair resource allocation mechanism is used so that (1) the number of affected TCP flows is minimized, and (2) we provide sufficient resource protection for the affected TCP flows. We report experimental results to quantify the robustness and accuracy of the proposed detection mechanism and the efficiency of the defense method.