Sciweavers

DISCEX
2003
IEEE

NetBouncer: Client-legitimacy-based High-performance DDoS Filtering

14 years 5 months ago
NetBouncer: Client-legitimacy-based High-performance DDoS Filtering
We describe "NetBouncer", an approach and set of technologies for providing practical and highperformance defenses against distributed denial-ofservice (DDoS) attacks. The central innovation in the NetBouncer approach to filtering and mitigating DDoS attacks is the ability to distinguish legitimate traffic from illegitimate ones so as to enable the discarding of only illegitimate traffic. In particular, this allows a NetBouncer-enabled network to distinguish DDoS congestion from flash crowd congestion situations. This provides a unique advantage over other DDoS mitigation techniques such as those based on filtering and congestion control where some loss of legitimate traffic is inevitable. The NetBouncer approach is characterized as an end-point-based solution to DDoS protection. It provides localized protection at potential choke points or bottlenecks that may exist in front of hosts and servers. NetBouncer attempts to block traffic as close to the victim as possible, while...
Roshan K. Thomas, Brian L. Mark, Tommy Johnson, Ja
Added 04 Jul 2010
Updated 04 Jul 2010
Type Conference
Year 2003
Where DISCEX
Authors Roshan K. Thomas, Brian L. Mark, Tommy Johnson, James Croall
Comments (0)