White Papers

TCP Flow Analysis for Defense Against Shrew DDoS Attacks

Overview The shrew or RoS attacks are low-rate DDoS attacks that degrade the QoS to end systems slowly but not to deny the services completely. These attacks are more difficult to detect than the flooding type of DDoS attacks. This paper explores the energy distributions of Internet traffic flows in frequency domain. Normal TCP traffic flows present some form of periodicity because of TCP protocol behavior. The results reveal that normal TCP flows can be segregated from malicious flows using some energy distribution properties. The paper discovers the spectral shifting of attack flows from that of normal flows. Combining flow-level spectral analysis with sequential hypothesis testing, a novel defense scheme against shrew DDoS or RoQ (reduction-of-service) attacks is proposed.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
University of Southern California
File Format
PDF
Date Published
Oct 31, 2007
Format
White Papers
Topics
TCP - IP

Similiar White Papers

A Taxonomy of the Linux Network Stack

A Taxonomy of the Linux Network Stack

This paper tries to give readers not familiar with the Linux network stack a gentle introduction to the fundamental conc

Publisher: Oracle  |  Tags: data, ip, kernel, linux, network

Cisco - Access Control Lists and IP Fragments

Cisco - Access Control Lists and IP Fragments

This white paper explains the different kinds of Access Control List (ACL) entries and what happens when different kinds

Publisher: Cisco Systems  |  Tags: ip

Magic Quadrant for Unified Communications, 2007

Magic Quadrant for Unified Communications, 2007

Unified Communications (UC) offer the ability to significantly improve how individuals, groups and companies interact an

Publisher: Gartner  |  Tags: applications, business applications, ip, pbx, uc, unified, unified messaging, voip

How Cisco IT Deploys Closed-Circuit TV Cameras Over the Secure IP Network

How Cisco IT Deploys Closed-Circuit TV Cameras Over the Secure IP Network

Cisco uses video surveillance to help keep its work environment secure. Two years ago, Cisco used a combination of camer

Publisher: Cisco Systems  |  Tags: cctv, data, digital, ip, network, surveillance, tv

VLAN Load Balancing Between Trunks Using the Spanning-Tree Protocol Port Priority

VLAN Load Balancing Between Trunks Using the Spanning-Tree Protocol Port Priority

This paper provides the theory behind VLAN load balancing between trunks, and also provides configuration examples for s

Publisher: Cisco Systems  |  Tags: ip

University of Southern California White Papers

Cross Layer Adaptive Control for Wireless Mesh Networks

Cross Layer Adaptive Control for Wireless Mesh Networks

This paper investigates optimal routing and adaptive scheduling in a wireless mesh network composed of mesh clients and

Publisher: University of Southern California  |  Tags: mobility, network, routers

Policy-Based Resource Management and Service Provisioning in GMPLS Networks

Policy-Based Resource Management and Service Provisioning in GMPLS Networks

Emerging network applications tend to be built over heterogeneous network resources spanning multiple management domains

Publisher: University of Southern California  |  Tags: applications, management, mpls, network, nsf

Decentralized Utility-Based Sensor Network Design

Decentralized Utility-Based Sensor Network Design

Wireless sensor networks consist of energy constrained nodes operating typically in an unattended mode and highly dynami

Publisher: University of Southern California  |  Tags: data, network

Global Acceptance of Technology (GAT) and Demand for Mobile Data Services

Global Acceptance of Technology (GAT) and Demand for Mobile Data Services

Social transformations are envisioned to occur with the increased diffusion of mobile data services, once technology and

Publisher: University of Southern California  |  Tags: data, data services, mobile data

Delay Analysis and Comparison of OFDM-TDMA and OFDMA Under IEEE 802.16 QoS Framework

Delay Analysis and Comparison of OFDM-TDMA and OFDMA Under IEEE 802.16 QoS Framework

The delay analysis and comparison of OFDM-TDMA and OFDMA using a flow control scheme under the QoS framework of IEEE 802

Publisher: University of Southern California  |  Tags: applications, cdma, qos, real-time, verified