TCP - IP White Papers
High-Speed Router Filter for Blocking TCP Flooding Under DDoS Attack
Overview This paper presents a hardware solution that can reliably block most of the malicious TCP traffic at the edge routers while passing the legitimate TCP traffic during the Distributed Denial-of-Service (DDoS) attack. By allocating bandwidths separately for TCP, the TCP portion of the bandwidth can be protected. In simulation study, the filter successfully blocked 99.9% of the attack traffic while legitimate traffic showed nearly identical performance as in the non-attacked condition. This filtering is transparent to the hosts or routers and a filtering device can be easily attached to router ports.
| Publisher | Case Western Reserve University | File Format | |
|---|---|---|---|
| Date Published | February 2004 | ||
| Format | White Papers | ||
| Topics | |||



