CHEN Wei, LUO Xu-cheng, QIN Zhi-guang. IP Spoofing DDoS Defense Using Active IP Record and ICMP Message[J]. Journal of University of Electronic Science and Technology of China, 2007, 36(6): 1183-1186.
Citation: CHEN Wei, LUO Xu-cheng, QIN Zhi-guang. IP Spoofing DDoS Defense Using Active IP Record and ICMP Message[J]. Journal of University of Electronic Science and Technology of China, 2007, 36(6): 1183-1186.

IP Spoofing DDoS Defense Using Active IP Record and ICMP Message

  • This paper describes the principle of Distributed Denial of Service (DDoS) attack. Several representative defense methods are analyzed to against it. A defense method against IP spoofing DDoS attack is proposed. An active IP record table is used to detect all IP packets passing through the border of autonomy system in this method. Packets of the source IP address which are not active will be discarded by the border routers or routers near the border in the autonomy system, according to the Internet Control Message Protocol (ICMP) protocol, timeout ICMP messages will be sent to the source IP hosts, and thus, IP spoofed packets will be discarded, because their source IP usually are not active. Although some legal packets will also be discarded, the retransmission will be triggered by the timeout ICMP messages immediately.
  • loading

Catalog

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return