Effective mechanisms for detecting and thwarting Distributed Denial-of-Service (DDoS) attacks are becoming increasingly important to the success of today’s Internet as a viable commercial and business tool. Most earlier work on the DDoS-detection problem has typically focused on either off-line analyses of DDoS-attack measurements or on techniques targeting a small number of potential victim destinations; unfortunately, such mechanisms are not useful for detecting possible DDoS activity in real time over large ISP networks, where the number of packet destinations to monitor can easily rise to several millions. In this paper, we propose novel data-streaming algorithms for the robust, real-time detection of DDoS activity in large ISP networks. The key element of our solution is a new, hash-based synopsis data structure for network-data streams that allows us to efficiently track, in guaranteed small space and time, destination IP addresses in the underlying network that are “large...
Sumit Ganguly, Minos N. Garofalakis, Rajeev Rastog