Active Countermeasure Platform against DDoS Attacks(Regular Section)
スポンサーリンク
概要
- 論文の詳細を見る
Distributed Denial of Service (DDoS) attacks are a pressing problem on the Internet as demonstrated by recent attacks on major e-commerce servers and ISPs. Since the attack is highly distributed, an effective solution must be formulated with a distributed approach. Recently, some solutions, in which intermediate network nodes filter or shape congested traffic, have been proposed. These solutions may decrease the congested traffic, but they still cause "collateral victims problem," that is, legitimate packets may be discarded mistakenly. In this paper, we propose Active Countermeasure Platform to minimize traffic congestion and to address the collateral victim problem using the Active Networks paradigm, which incorporates programmability into intermediate network nodes. Our platform can prevent overloading of the target and consuming the network bandwidth of both the backbone and the protected site autonomously. In addition, it can improve the collateral victim problem based on user policy. This paper shows the concept of our platform, system design and evaluation of the effectiveness using a prototype.
- 社団法人電子情報通信学会の論文
- 2002-12-01
著者
-
Shigeno Hiroshi
Faculty of Science and Technology, Keio University
-
Okada Ken-ichi
Faculty of Science and Technology, Keio University
-
Okada Ken-ichi
Faculty Of Science And Technology Keio University
-
Okada Ken-ichi
Department Of Information And Computer Science Faculty Of Science And Technology Keio University
-
Machida Shuichi
Faculty Of Science And Technology Keio University:(present Address)sun Microsystems K.k.
-
Chen E
Ntt Information Sharing Platform Lab. Kanagawa Jpn
-
KASHIWA Dai
NTT Information Sharing Platform Laboratories
-
CHEN Eric
NTT Information Sharing Platform Laboratories
-
FUJI Hitoshi
NTT Information Sharing Platform Laboratories
-
MATSUSHITA Yutaka
Faculty of Science and Technology, Keio University
-
Kashiwa Dai
Ntt Information Sharing Platform Laboratories:faculty Of Science And Technology Keio University
-
Shigeno H
Faculty Of Science And Technology Keio University
-
Shigeno Hiroshi
Faculty Of Science And Technology Keio University
-
Matsushita Y
Tokyo Univ. Technol.
関連論文
- NAL Level Stream Authentication for H.264/AVC (特集:シームレスコンピューティングとその応用技術)
- NAL Level Stream Authentication for H.264/AVC
- NAL Level Stream Authentication for H.264/AVC
- Two Cases of Ductal Adenoma of the Breast
- A JPEG Codec Adaptive to the Relative Importance of Regions in an Image
- A Video Copyright Protection System Based on ContentID
- Fair Bandwidth Allocation in Diffserv Networks(Network Quality and Control)(Next Generaton Mobile Communications Systems)
- Authentication with 3-D Pattern Communication
- Active Countermeasure Platform against DDoS Attacks(Regular Section)
- Is Histopathological Evidence Really Essential for Making a Surgical Decision About Mucinous Carcinoma Arising in a Perianal Fistula? : Report of a Case
- Pancreatobiliary Fistula Associated with an Intraductal Papillary-Mucinous Pancreatic Neoplasm Manifesting as Obstructive Jaundice : Report of a Case
- Necrotizing fasciitis secondary to carcinoma of the gallbladder with perforation
- Hit-list Worm Detection Using Distributed Sliding Window
- Improvements in TCP Robustness for Asymmetric Bandwidth
- TINA-Based Scalable Model for Personal Mobility Service(Special Section on Multi-dimensional Mobile Information Networks)
- An Interworking Architecture between TINA-Like Model and Internet for Mobility Services (Special Issue on Network Interworking)
- The distance of tumor spread in the main pancreatic duct of an intraductal papillary-mucinous neoplasm : where to resect and how to predict it
- Nonfunctioning Pancreatic Endocrine Tumor with Extension into the Main Pancreatic Duct : Report of a Case
- A Real-Time Stream Authentication Scheme for Video Streams (特集:ブロードバンド・ユビキタス・ネットワークとその応用)
- d-ACTM/VT : A Distributed Virtual AC Tree Detection Method(Network Security)
- Improvements in TCP Robustness for Asymmetric Bandwidth
- A Real-Time Stream Authentication Scheme for Video Streams
- A Real-Time Stream Authentication Scheme for Video Streams
- Leiomyosarcoma of the Pancreas : Report of a Case
- Improvements in TCP Robustness for Asymmetric Bandwidth
- d-ACTM/VT: A Distributed Virtual AC Tree Detection Method
- d-ACTM/VT: A Distributed Virtual AC Tree Detection Method