Identification of legitimate addresses under DDoS attacks with random spoofed source addresses

Jun Xiao,XiaoChun Yun,Yongzheng Zhang,Lei Dai
DOI: https://doi.org/10.3772/j.issn.1002-0470.2011.04.005
2011-01-01
Abstract:An efficient data structure called Extended Counting Bloom Filter (E-CBF) was designed to count the number of packets from source IP addresses, and then, based on it, an identifying algorithm with the time complexity of O(1) and the memory space of only 1 MB, was proposed for finding legitimate addresses under distributed denial of service (DDoS) attacks with random spoofed source addresses. Based on the analysis of identifying errors, an algorithm for adjusting identifying parameters was also proposed, which can automatically adjust the parameters to satisfy the precision requirement according to attack scales. The simulation and real traffic experiments show that the proposed method can automatically adjust the parameters to fast and accurately identify legitimate addresses under different attack scales.
What problem does this paper attempt to address?