An IP traceback assisted hierarchical defense overlay against DDoS attacks

Yinan Jing,Xueping Wang,Xiaochun Xiao,Gendu Zhang
2006-01-01
Journal of Information and Computational Science
Abstract:Distributed denial-of-service attack has become one of the major threats to Internet today. The distributed nature of DDoS problem needs a distributed solution. In this paper, we propose using a hierarchical domain-aware overlay to construct a secure cooperative environment for distributed rate limit. This distributed defense framework has a service-oriented economic model that not only motivates ISPs to deploy it, but also benefits all participants. In addition, an IP traceback-based rate limit algorithm is proposed to leverage the IP traceback technique not only to mitigate the DDoS attack effect as close to attack sources as possible, but also to improve the throughput of legitimate traffic even under a meek attack.
What problem does this paper attempt to address?