Telecommunications Science ›› 2012, Vol. 28 ›› Issue (10): 88-93.doi: 10.3969/j.issn.1000-0801.2012.10.015

• research and development • Previous Articles     Next Articles

An OTP-Based Mechanism for Defending Application Layer DDoS Attacks

Xi Ye1,2,Wushao Wen2,Yiru Ye1   

  1. 1 Department of Computer, Wenzhou Medical College, Wenzhou 325035,China
    2 School of Software, Sun Yat-Sen University, Guangzhou 510275, China
  • Online:2012-10-15 Published:2017-07-05

Abstract:

In this paper, we present the design and implementation of OTP-DEF, a kernel extension to protect web servers against application layer DDoS attacks. First of all, according to the load of web server, an OTP-DEF web server should fall into one of three following modes: normal, suspected attack or confirmed attack mode, and the OTP-DEF authentication mechanism shall only be activated when web server is in suspected attack mode. Secondly, we use OTP as our puzzle, which can automatically change at the certain time interval. It makes our proposal can defend copy attacks, replay attacks and Brute-Force Attack. Thirdly, OTP-DEF uses an intermediate stage to identify the IP addresses that ignore the test, and persistently bombard the server with requests despite repeated failures at solving the puzzles. Once these machines are identified, OTP-DEF blocks their requests, turns the tests off, and allows access to legitimate users who are unable or unwilling to solve tests. Finally, OTP-DEF requires no modifications to client software.

Key words: DDoS attack, OTP, puzzle, web service, application layer

No Suggested Reading articles found!