A simple response packet confirmation method for DRDoS detection
Hiroshi Tsunoda, Yoshihiro NEMOTO, K. Ohta, Atsunori Yamamoto
Abstract
Hiroshi Tsunoda, Yoshihiro NEMOTO, K. Ohta, Atsunori Yamamoto
Abstract
In this paper, we propose a simple but tough method for confirming response packets to detect DRDoS attack packets. In DRDoS attacks, the victim suffers from reflected response packets from legitimate hosts, and it is difficult to distinguish attack packets from legitimate packets. We focus on the fact that the types of packet used for DRDoS are limited and predictable. Thus, the proposed method uses only a pair of request/response, and does not need complicated state management like the stateful inspection method. We demonstrate that the proposed method can accurately detect DRDoS packets with fewer cost.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In this paper, we propose a simple but tough method for confirming response packets to detect DRDoS attack packets. In DRDoS attacks, the victim suffers from reflected response packets from legitimate hosts, and it is difficult to distinguish attack packets from legitimate packets. We focus on the fact that the types of packet used for DRDoS are limited and predictable. Thus, the proposed method uses only a pair of request/response, and does not need complicated state management like the stateful inspection method. We demonstrate that the proposed method can accurately detect DRDoS packets with fewer cost.
Key concepts: Network packet, Stateful firewall, Computer science, Simple (philosophy), Focus (optics), Computer network, Deep packet inspection, Real-time computing