Introduction Most modern attacks/intrusions are very intelligent leaving no trace of the appearance in the network making detection very difficult. DDoS attack is classified as resource depletion attacks and bandwidth depletion attacks [1]. Protocol exploit attacks and malformed packet attack tie up the critical resources of the victim system. Many of these attacks also use spoofed source IP addresses, thereby eluding source identification. The two most basic types of DDoS attacks are 1) Bandwidth attacks and 2) Application attacks. Bandwidth attacks consume resources such as network bandwidth or equipment by overwhelming with a high volume of packets [2]. Due to overload of packets targeted routers, servers, and firewalls can be rendered unavailable to process valid transactions. Packet-flooding is a form of bandwidth attack in which a large number of seemingly legitimate TCP, User Datagram Protocol (UDP), or Internet Control Message Protocol (ICMP) packets are directed to a specific destination [2]. To make detection difficult these kinds of attacks spoof their source address to prevent identification. Application attacks use the expected behavior of protocols such as TCP and HTTP to the attacker’s advantage by tying up computational resources and preventing them from processing transactions or requests. Any computer in the network can be easily compromised by DDoS attacks without the knowledge of being attacked. Sophisticated and automated DDoS attack tools like Trinoo, TFN, TFN2K, mstream, Stacheldraht, Shaft, Trinity, Knight etc., available in the Internet do not require technical knowledge to launch a high rate flooding attack. The victims are surprisingly government agencies, financial corporations, defense agencies and m... ... middle of paper ... animals,” International Society for Behavioral Ecology, vol. 14, pp. 719-723, 2003. [31] Zhongwen Li and Yang Xiang, “Mathematical Analysis of Active DDoS Defense Systems,” International Conference on Computational Intelligence and Security, Guangzhou, pp. 1563-1566, 2006. [32] G. Preetha, B.S. Kiruthika Devi, S. Mercy Shalinie, “Combat Model based DDoS Detection and Defense using Experimental Testbed: A Quanitative Approach,” International Journal of Intelligent Engineering and Informatics (IJIEI), vol. 1, no. ¾, pp. 261-279, 2011. [33] The Swiss Education and Research Network - Default TTL values in TCP/IP (2002) [Online]. Available: default.html. [34] Jaehak Yu, Hansung Lee, Myung-Sup Kim, Daihee Park, “Traffic flooding attack detection with SNMP MIB using SVM,” Comput. Com, vol. 31, no. 17, pp. 4212-4219, 2008.

