Title
An Active Detecting Method Against SYN Flooding Attack
Abstract
SYN flooding attacks are a common type of Distributed Denial-of-Service (DDoS) attack. Early detection is desirable but traditional passive detection methods are inaccurate in the early stages due to their reliance on passively sniffing an attacking signature. The method presented in this paper captures attacking signatures using an active probing scheme that ensures the efficient early detection. The active probing scheme DARB obtains the delay of routers by sending packets containing special Time-to-Live set at the IP headers. The results of the probe are used to perform SYN flooding detection, which is reliable and with little overhead. This approach is more independent than other methods that require cooperation from network devices. Experiments show that this delay-probing approach distinguishes half-open connections caused by SYN flooding attacks from those arising from other causes accurately and at an early stage.
Year
DOI
Venue
2005
10.1109/ICPADS.2005.67
ICPADS (1)
Keywords
Field
DocType
computer science,distributed computing,network device,distributed denial of service attack,ddos attack,helium,distributed denial of service,filtering,time to live,ddos
Early detection,Denial-of-service attack,Computer science,Passive detection,Network packet,Networking hardware,Sniffing,Computer network,Filter (signal processing),Real-time computing,SYN flood
Conference
Volume
Issue
ISBN
1
null
0-7695-2281-5-01
Citations 
PageRank 
References 
16
1.01
19
Authors
4
Name
Order
Citations
PageRank
Bin Xiao11763129.31
Wei Chen28612.45
Yanxiang He356868.23
Edwin Hsing-Mean Sha41378.49