Publication | Closed Access
DiDDeM: a system for early detection of TCP SYN flood attacks
34
Citations
17
References
2005
Year
Unknown Venue
Ddos DetectionEngineeringData ScienceIntrusion Detection SystemInformation SecurityProgram AnalysisDenial-of-service AttackIntrusion ToleranceStateless Signature DetectionDenial-of-service AttacksComputer ScienceInternet Of ThingsEarly DetectionNetwork Traffic MeasurementNetwork MonitoringFilter Traffic
This paper presents the distributed denial-of-service detection mechanism (DiDDeM) system for early detection of denial-of-service attacks. The design requirements of the system are posited to demonstrate the requirements for an early detection system. An overview of the system is presented to show how these requirements are met. DiDDeM provides a two-tier detection approach. First, pre-filters (PFs) filter traffic for possible attacks. This is achieved through the application of both stateful and stateless signatures utilising routing congestion algorithms. Second, command and control (C/sup 2/) servers provide intra- and inter-domain co-operation and response to contain an attack within the routing infrastructure. The results for stateful and stateless signature detection of TCP SYN flood attacks are presented.
| Year | Citations | |
|---|---|---|
Page 1
Page 1