Programmable Traffic Monitoring Method Based on Active Network Techniques and Application to DDoS Detection

Shigehiro ANO

IEICE TRANSACTIONS on Communications   Vol.E87-B    No.7    pp.1890-1899
Publication Date: 2004/07/01
Online ISSN: 
Print ISSN: 0916-8516
Type of Manuscript: Special Section PAPER (Special Section on Next Generation Networks Software)
Category: Security Issues
active network,  traffic monitor,  network management,  DDoS,  

Full Text: PDF>>
Buy this Article

As the Internet has become the infrastructure for the global communication, the quality degradation due to network failures and illegal traffic such as DDoS (Distributed Denial of Service) have become a serious problem. In order to solve the problem, a network monitoring system that monitors the traffic of Internet in real time is strongly desired. Traffic monitors that collect the statistics from captured packets play a key roll in the system; however, they are not flexible enough for being used in the rapidly changing Internet. The traditional approach such that a new traffic monitor is developed for a new requirement results in a long turn around time of the development. Therefore, we have proposed a flexible network monitoring system that consists of programmable traffic monitors. Traffic monitors are made programmable by introducing active network techniques; therefore, we call the network monitoring system as the programmable monitor network. This paper describes the implementation of the programmable monitor network and its application to DDoS (Distributed Denial of Service) attack detection.