Journal of System Simulation ›› 2017, Vol. 29 ›› Issue (11): 2898-2902.doi: 10.16182/j.issn1004731x.joss.201711040

Previous Articles     Next Articles

Line-rate Defenses Approach against 10 Gbps DDoS Attacks

Su Cheng1, Wang Wentong2, Yang Shibao1, Xv Linlin3, Tang Xinan4   

  1. 1. 3 JiLing University of Tech., Najing 211106, China, China;
    2. JiangSu Senseit Electronics Tech. Co. Ltd, Wuxi 214135, China;
    3. Henuo Tech. Beijing Co. Ltd, Beijing 100055, China;
    4. Nanjing Yunlilai software tech. Co. Ltd, Nanjing 211100, China
  • Received:2016-05-31 Published:2020-06-05

Abstract: Defenses approach against DDoS(Distributed Denial of Service) attacks is currently an important hot issues. We propose a new efficient defenses approach which adopts a detection system based on metadata analysis to identify the packages of DDoS attacks. The flow control rules are formed based on the summarized experience data. ACL (Access Control List) is applied through inline devices (firewalls and load balancers) or divider to limit rate, clean flow or drop package. 10Gbps bandwidth HTTP requests, which contain malicious DDoS attacks packages, can be detected and cleaned completely in line-rate speed. We especially summarize th traffic characteristics of main domestic DDoS attacks.

Key words: DDOS, HTTP GET flooding attacks, meta-data analysis, intelligence probe

CLC Number: