Skip to main content

An empirical analysis of target-resident DoS filters

Publication ,  Conference
Collins, M; Reiter, MK
Published in: Proceedings - IEEE Symposium on Security and Privacy
August 16, 2004

Numerous techniques have been proposed by which an end-system, subjected to a denial-of-service flood, filters the offending traffic. In this paper, we provide an empirical analysis of several such proposals, using traffic recorded at the border of a large network and including real DoS traffic. We focus our analysis on four filtering techniques, two based on the addresses from which the victim server typically receives traffic (static clustering and network-aware clustering,), and two based on coarse indications of the path each packet traverses (hop-count filtering and path identifiers). Our analysis reveals challenges facing the proposed techniques in practice, and the implications of these issues for effective filtering. In addition, we compare techniques on equal footing, by evaluating the performance of one scheme under assumptions made by another. We conclude with an interpretation of the results and suggestions for further analysis.

Duke Scholars

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

Publication Date

August 16, 2004

Volume

2004

Start / End Page

103 / 114
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Collins, M., & Reiter, M. K. (2004). An empirical analysis of target-resident DoS filters. In Proceedings - IEEE Symposium on Security and Privacy (Vol. 2004, pp. 103–114). https://doi.org/10.1109/SECPRI.2004.1301318
Collins, M., and M. K. Reiter. “An empirical analysis of target-resident DoS filters.” In Proceedings - IEEE Symposium on Security and Privacy, 2004:103–14, 2004. https://doi.org/10.1109/SECPRI.2004.1301318.
Collins M, Reiter MK. An empirical analysis of target-resident DoS filters. In: Proceedings - IEEE Symposium on Security and Privacy. 2004. p. 103–14.
Collins, M., and M. K. Reiter. “An empirical analysis of target-resident DoS filters.” Proceedings - IEEE Symposium on Security and Privacy, vol. 2004, 2004, pp. 103–14. Scopus, doi:10.1109/SECPRI.2004.1301318.
Collins M, Reiter MK. An empirical analysis of target-resident DoS filters. Proceedings - IEEE Symposium on Security and Privacy. 2004. p. 103–114.

Published In

Proceedings - IEEE Symposium on Security and Privacy

DOI

Publication Date

August 16, 2004

Volume

2004

Start / End Page

103 / 114