A collaborative approach for proactive detection of distributed denial of service attacks - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2007

A collaborative approach for proactive detection of distributed denial of service attacks

Résumé

Distributed Denial of Service attacks (DDoS) are a major threat to the Internet and detecting this kind of attacks as far as possible from the victim and close as possible to its source is a real challenge. We propose a new framework named FireCollaborator to deal with this problem on the Internet Service Provider (ISP) level, based on collaborating Intrusion Prevention Systems (IPS). A potential victim asks and pays the ISP to be protected. The key point is to use compressed metrics (i.e., frequency and entropy) based on the routing rules in order to extract suspected flows. The information and alerts are shared amongst the IPSs to enhance their believes about the network status and thus to counter the attacks far away from the victim and to save the network resources.
Fichier principal
Vignette du fichier
monam.pdf (167.12 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00188020 , version 1 (01-10-2008)

Identifiants

  • HAL Id : inria-00188020 , version 1

Citer

Jérôme François, Adel El-Atawy, Ehab Al Shaer, Raouf Boutaba. A collaborative approach for proactive detection of distributed denial of service attacks. IEEE Workshop on Monitoring, Attack Detection and Mitigation - MonAM'2007, Nov 2007, Toulouse, France. ⟨inria-00188020⟩
259 Consultations
196 Téléchargements

Partager

Gmail Facebook X LinkedIn More