Two Layer Defending Mechanism against DDoS Attacks

 Distributed Denial of Service (DDoS) attackers make a service unavailable for intended users. Attackers use IP spoofing as a weapon to disguise their identity. Th e spoofed traffic follows the same principles as normal traffic, so detection and filtering is very essential. Hop Count Filterin g (HCF) scheme identifies packet whose source IP ad dress is spoofed. The information about a source IP address and it s corresponding hops from a server (victim) re corded in a table at the victim. The incoming packet is checked against this table for authenticity. The design of IP2HC table reduces the amount of storage space by IP address clustering. The propose d work filters majority of the spoofed traffic by Hop Count Filter.Support Vector Machine   (HCF.SVM) algorithm on the network layer. DDoS attac kers using genuine IP is subjected to traffic limit at the application layer. The two layer defense approa ch protects legitimate traffic from being denied, thereby mitigating DDoS effectively. HCF.SVM model yields 98.99% accuracy w ith reduced False Positive (FP) rate and the rate limiter punishes the aggressive flows and provides sufficient bandwidth for legitimate users without any denial of service. The implementation of the proposed work is carried out on an experimental testbed.  

[35] Yaar A., Perrig A., and Song D., StackPi: New Packet Marking and Filtering Mechanisms for DDoS and IP spoofing Defense, the IEEE Journal on Selected Areas in Communications , vol. 24, no. 10, pp. 1853-1863, 2006. Kiruthika Devi Bodinayakanur Subramanian is currently pursuing MS (by Research) at Anna University. She received her BE degree in electronics and communication engineering from Coimbatore Institute of Engineering and Information Technology in 2006. Her current research interests include network security and machine learning. Preetha Gunasekaran is currently pursing PhD degree at Anna University. She received her MSIT in information technology in 2002 and MPhil in Computer Science from Madurai Kamaraj University in 2005. She worked as a Lecturer from 2002 to 2008. Her current research interests includ e network security and wireless adhoc networks. Mercy Shalinie Selvaraj is currently the Head of the Department of Computer Science and Engineering at Thiagarajar College of Engineering. She has published several papers in International Journals/ Conferences. Her current areas of interest include machine learn ing, neural networks and information security.