Sciweavers

ICDCSW
2005
IEEE

MAFIC: Adaptive Packet Dropping for Cutting Malicious Flows to Push Back DDoS Attacks

13 years 10 months ago
MAFIC: Adaptive Packet Dropping for Cutting Malicious Flows to Push Back DDoS Attacks
— In this paper, we propose a new approach called MAFIC (MAlicious Flow Identification and Cutoff) to support adaptive packet dropping to fend off DDoS attacks. MAFIC works by judiciously issuing lightweight probes to flow sources to check if they are legitimate. Through such probing, MAFIC would drop malicious attack packets with high accuracy while minimizes the loss on legitimate traffic flows. Our NS-2 based simulation indicates that MAFIC algorithm drops packets from unresponsive potental attack flows with an accuracy as high as 99% and reduces the loss of legitimate flows to less than 3%. Furthermore, the false positive and negative rates are low–only around 1% for a majority of the cases.
Yu Chen, Yu-Kwong Kwok, Kai Hwang
Added 24 Jun 2010
Updated 24 Jun 2010
Type Conference
Year 2005
Where ICDCSW
Authors Yu Chen, Yu-Kwong Kwok, Kai Hwang
Comments (0)