Current IP-based Internet has exposed many problems in term as Mobility, Security and Utility. Stateful Forwarding is a popular idea to mitigate these problems, however, it introduces some new varietal DDOS attacks. Which have similar characteristic among all Stateful Forwarding paradigms. This paper proposes a mechanism called Enhanced Disabling Resource Exhaustion (EDRE) to detect these new attacks accurately. EDRE counts all expired State-entries to determine the router is under attacks or not, and forwards packets through a Packet-Marking method, rather than Forwarding-State-Table. EDRE diverts the malicious packets out of Forwarding-State-Table effectively. Besides, this paper presents a max-utility and threshold-based measure to detect attacks, and proposes a method to select the threshold optimally. In addition, our design is rooted in Game Theory. Simulation results show EDRE false negatives rate can decrease by 26%, while false positives rate only increase by 3.5%, false negatives rate is more important than false positives rate in general. EDRE can significantly detect new varietal DDOS attacks compared to other existing measures.
hello, everyone! Could you please point out some presentation problems in the paragraph.
Thanks.
Your introduction has some grammatical problems. These are noted by highlighting and in-line comments. ) many problems in term as Mobility, Security and Utility.
New words, one handy idiom, and a 2-minute quiz — delivered to your inbox to keep your streak alive.
Your introduction has some grammatical problems. These are noted by highlighting and in-line comments.
Current IP-based Internet has exposed (?) many problems in term as Mobility, Security and Utility. Stateful Forwarding is a popular idea to mitigate these problems, however, it introduces some new varietal DDOS (Spell