Preventing DDoS attacks by identifier/locator separation

Identifier/locator separation is a promising solution to the current Internet scaling problems. In this article, we argue that identifier/location separation can also help prevent distributed denial-of-service (DDoS) attacks. We discuss an identifier-to-locator mapping approach and explain how the approach makes it difficult for attackers to control botnets. We also present numerical results based on data from a real DDoS attack to demonstrate that, even if many zombies attack a victim, identifier/locator separation helps detect DDoS attacks.