] Research on DDoS Filtering Algorithm based on Bloom Filter WhiteList

被引:1
|
作者
Peng, Dan [1 ,2 ]
Chang, Guiran [1 ]
Guo, Rui [3 ]
Tang, Yanjun [2 ]
机构
[1] Northeastern Univ, Coll Informat Sci & Engn, Shenyang, Peoples R China
[2] China Criminal Police Univ, Shenyang, Peoples R China
[3] Tsinghua Univ, Dept Comp Sci & Tech, Beijing, Peoples R China
关键词
DDoS attack; Genetic algorithm; Netflow; Worm;
D O I
10.1109/MMIT.2008.105
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
With the DDoS(distributed denial of service) traffic which was implemented using depleted bandwidth is filtered by routers in high speed network, it is impossible for the victim to work on the individual level of on-going traffic flows. The scheme establishes the source and destination IP address database by observing the normal traffic and storages it in a Bloom Filter table. The Netflow statistics is mainly used to allocate the weights for traffic routing by routers. A new algorithm is thus proposed to get efficiently maximum throughput by the traffic filtering, and its feasibility and validity have been verified in real network circumstances. The algorithm shows its advantages that it just occupies a small part of resources. Moreover, it can optimize the network traffic simultaneously with defending against DDoS attack, thus eliminating efficiently the global burst of traffic arising from normal traffic so as to improve greatly the efficiency of servers.
引用
收藏
页码:291 / +
页数:3
相关论文
共 50 条
  • [41] Adaptive DDOS filtering based on history information
    Dai, SD
    Yang, F
    Duan, HX
    Li, X
    ICCC2004: Proceedings of the 16th International Conference on Computer Communication Vol 1and 2, 2004, : 1080 - 1084
  • [42] Efficient dynamic packet filtering program based on shared-node counting Bloom filter
    Wang, Jie
    Shi, Cheng-Hui
    Liu, Ya-Bin
    Xi Tong Gong Cheng Yu Dian Zi Ji Shu/Systems Engineering and Electronics, 2009, 31 (09): : 2227 - 2231
  • [43] Research on counter bandwidth depletion DDoS attacks based on Genetic algorithm
    Guo, Rui
    Chang, Guiran
    Hou, Ruidong
    Qin, Yuhai
    Sun, Baojing
    liu, An
    Jia, Yan
    Peng, Dan
    ICNC 2007: THIRD INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 4, PROCEEDINGS, 2007, : 155 - +
  • [44] Page Replacement Algorithm Based on Counting Bloom Filter for NAND Flash Memory
    Liu, Jun
    Chen, Shuyu
    Wang, Guiping
    Wu, Tianshu
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2014, 60 (04) : 636 - 643
  • [45] Intrusion Detection Algorithm of Industrial Control System Based on Improved Bloom Filter
    Chen, Yanru
    Zhang, Yuanyuan
    Lin, Youlin
    Huang, Xinmao
    Xing, Bin
    Long, Ping
    Li, Yang
    Chen, Liangyin
    COMPUTER SUPPORTED COOPERATIVE WORK AND SOCIAL COMPUTING, CHINESECSCW 2021, PT I, 2022, 1491 : 164 - 175
  • [46] A Bloom Filter-Based Algorithm for Routing in Intermittently Connected Mobile Networks
    Sanchez-Hernandez, Jairo
    Menchaca-Mendez, Rolando
    Menchaca-Mendez, Ricardo
    Garcia-Diaz, Jesus
    Rivero-Angeles, Mario E.
    Garcia-Luna-Aceves, J. J.
    MSWIM'15: PROCEEDINGS OF THE 18TH ACM INTERNATIONAL CONFERENCE ON MODELING, ANALYSIS AND SIMULATION OF WIRELESS AND MOBILE SYSTEMS, 2015, : 319 - 326
  • [47] A Cancelable Multi-Biometric Template Generation Algorithm Based on Bloom Filter
    You, Lin
    Li, Xun
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2018, PT III, 2018, 11336 : 547 - 559
  • [48] SSL VPN resources log optimization techniques based on Bloom Filter algorithm
    Song, Yongchun
    Li, Hongxin
    Cheng, Lin
    Xiang, Mingming
    Cai, Jiawei
    2016 IEEE INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2016, : 733 - 736
  • [49] GA-Based Filtering Algorithm to Defend against DDoS Attack in High Speed Network
    Wang, Shen
    Guo, Rui
    ICNC 2008: FOURTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 1, PROCEEDINGS, 2008, : 601 - +
  • [50] GA-based filtering algorithm to defend against DDoS attack due to bandwidth depletion
    School of Information Science and Engineering, Northeastern University, Shenyang 110004, China
    不详
    Dongbei Daxue Xuebao, 2008, 3 (324-327):