A lightweight mechanism to mitigate application layer DDoS attacks

  • Jie Yu*
  • , Chengfang Fang
  • , Liming Lu
  • , Zhoujun Li
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Application layer DDoS attacks, to which network layer solutions is not applicable as attackers are indistinguishable based on packets or protocols, prevent legitimate users from accessing services. In this paper, we propose Trust Management Helmet (TMH) as a partial solution to this problem, which is a lightweight mitigation mechanism that uses trust to differentiate legitimate users and attackers. Its key insight is that a server should give priority to protecting the connectivity of good users during application layer DDoS attacks, instead of identifying all the attack requests. The trust to clients is evaluated based on their visiting history, and used to schedule the service to their requests. We introduce license, for user identification (even beyond NATs) and storing the trust information at clients. The license is cryptographically secured against forgery or replay attacks. We realize this mitigation mechanism and implement it as a Java package and use it for simulation. Through simulation, we show that TMH is effective in mitigating session flooding attack: even with 20 times number of attackers, more than 99% of the sessions from legitimate users are accepted with TMH; whereas less than 18% are accepted without it.

Original languageEnglish
Title of host publicationScalable Information Systems - 4th International ICST Conference, INFOSCALE 2009, Revised Selected Papers
Pages175-191
Number of pages17
DOIs
StatePublished - 2009
Event4th International ICST Conference on Scalable Information Systems, INFOSCALE 2009 - Hong Kong, Hong Kong SAR
Duration: 10 Jun 200911 Jun 2009

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering
Volume18 LNICST
ISSN (Print)1867-8211

Conference

Conference4th International ICST Conference on Scalable Information Systems, INFOSCALE 2009
Country/TerritoryHong Kong SAR
CityHong Kong
Period10/06/0911/06/09

Keywords

  • Application layer
  • DDoS attacks
  • Lightweight
  • Trust

Fingerprint

Dive into the research topics of 'A lightweight mechanism to mitigate application layer DDoS attacks'. Together they form a unique fingerprint.

Cite this