An Approach of Defending Against DDoS Attack

Wu Zhijun,Duan Haixin,Li Xing
DOI: https://doi.org/10.1007/s11767-005-0027-8
2006-01-01
Journal of Electronics (China)
Abstract:An approach of defending against Distributed Denial of Service (DDoS) attack based on flow model and flow detection is presented. The proposed approach can protect targets from DDoS attacking, and allow targets to provide good service to legitimate traffic under DDoS attacking, with fast reaction. This approach adopts the technique of dynamic comb filter, yields a low level of false positives of less than 1.5%, drops similar percentage of good traffic, about 1%, and passes neglectable percentage of attack bandwidth to the victim, less than 1.5%. The prototype of commercial product, D-fighter, is developed by implementing this proposed approach on Intel network processor platform IXP1200.
What problem does this paper attempt to address?