Design and Operational Characteristics of a Distributed Cooperative Infrastructure against DDoS Attacks

In this paper we present an inter-domain cooperative infrastructure against Distributed Denial of Service (DDoS) Attacks. The infrastructure is established between the networks that choose to participate. A software system, the Cooperative IDS Entity, is deployed at each participating domain. The main operational characteristics of this Entity and of the infrastructure as a whole are presented and a number of parameters that influence DDoS discovery and reaction efficiency are discussed. We also examine an operation scenario on actual topologies and attempt to demonstrate the validity of the concept.