




Abstract
Denial of Service attack continues to be a growing threat to the security of the Internet. In this thesis, we investigate low rate TCP targeted distributed denial of service (DDoS) attacks. A meticulously designed attack which exploits the fixed minimum RTO property of the TCP, can lead to performance degradation and a denial of service to legitimate users. This type of attacks is different from traditional flooding attacks, and hence conventional solutions to detect these attacks are not applicable. Existing solutions like End point RTO randomization and RED-PD schemes which can only mitigate the attack but cannot eliminate them. The randomization scheme also degrades the performance of the services in the absence of an attack. The aim here is not only to detect the attack but also perform the operation autonomously without modifying the existing TCP congestion control algorithms without introducing significant overheads. This thesis proposes a novel router based approach to efficiently detect and defend these attack flows at the edge routers.



