Detecting SYN Flooding Agents under Any Type of IP Spoofing

Detecting SYN Flooding Agents under Any Type of IP Spoofing
复制标题

DOI:
10.1109/icebe.2008.18
复制
发表时间:
2008-10
期刊:
2008 IEEE International Conference on e-Business Engineering
影响因子:
--
通讯作者:
Dalia Nashat;Xiaohong Jiang;S. Horiguchi
Dalia Nashat;Xiaohong Jiang;S. Horiguchi
中科院分区:
其他
文献类型:
--
作者:
Dalia Nashat;Xiaohong Jiang;S. Horiguchi

文献摘要

相似文献

TCP SYN洪泛攻击是最常见的DDoS攻击类型,会耗尽网络资源。一个基于路由器的检测方案已被提出来检测SYN洪泛代理的假设的基础上,SYN数据包从代理和SYN/ACK数据包从vicippsilas服务器通过不同的叶路由器。然而,在当前的IP欺骗技术中,攻击者可以欺骗来自任何子网的随机地址,因此来自代理的SYN数据包和来自服务器的SYN/ACK数据包可以通过相同的叶子路由器。因此,一个更通用和灵活的检测方案是非常需要的有效检测这些泛洪代理在任何类型的IP欺骗。在本文中,我们提出了这样一个计划来检测洪水代理考虑所有可能的IP欺骗。该方案基于TCP SYN-SYN/ACK协议对,并考虑了数据包报头信息(序列和Ack)。数字)。该方案采用计数布隆过滤器将所有到达子网的SYN/ACK数据包分为两个流,即第一个SYN/ACK数据包(SYN/ACKf)和重传的SYN/ACK数据包(SYN/ACKr),使方案具有普遍适用性,并采用累积和算法避免检测对站点和访问模式的依赖。与不考虑IP欺骗技术的旧检测方案相比,所提出的新方案可以显著提高SYN洪泛代理的检测准确性,基于不同IP欺骗技术的大量仿真结果验证了这一点。
The TCP SYN flooding attack is the most prevalent type of DDoS attacks that exhaust network resources. A router based detection scheme has been proposed to detect the SYN flooding agents based on the assumption that the SYN packets from the agent and the SYN/ACK packets from the victimpsilas server pass through different leaf routers. In the current IP spoofing techniques, however, the attacker can spoof a random address from any subnetwork, so the SYN packets from the agent and the SYN/ACK packets from the server may pass through the same leaf router. Therefore, a more general and flexible detection scheme is highly desirable for the efficient detection of these flooding agents under any type of IP spoofing. In this paper, we propose such a scheme to detect the flooding agents by considering all the possible kinds of IP spoofing. The proposed scheme is based on the TCP SYN-SYN/ACK protocol pair with the consideration of packet header information (both sequence and Ack. numbers). The Counting Bloom Filter is used to classify all the incoming SYN/ACK packets to the sub network into two streams, the first SYN/ACK packets (SYN/ACKf ) and the retransmission SYN/ACK packets (SYN/ACKr), to make our scheme generally applicable and the Cumulative Sum algorithm is applied to avoid the dependence of detection on sites and access patterns. Compared to the old detection scheme without the consideration of IP spoofing techniques, the proposed new scheme can significantly improve the accuracy in detecting the SYN flooding agents, as verified by extensive simulation results based on different IP spoofing techniques.