Research Article

SDNDefender: A Comprehensive DDoS Defense Mechanism Using Hybrid Approaches over Software Defined Networking

Table 4

Common malformed packet attacks.

AttackProtocolFeature

IP optionIPDF flag = 1, MF flag = 1 or DF flag = 1, offset > 0
TeardropIPOffsets are overlapped or staggered
IP nullIPProtocol field in the packet header is set to 0
CharGENUDP/TCPDestination port is set to 19
FraggleUDPDestination IP is a broadcast one, destination port is set to 7 or 19
SnorkUDPSource port is set to 7, 19, or 135, destination port is set to 135
SmurfICMPSource IP is set to a broadcast one
Ping of deathICMPPacket’s length is bigger than 65535 bytes
LandTCPSYN packet’s source IP is same to its destination IP
WinNukeTCPDestination port is set to 139, URG flag = 1
TCP optionTCPSYN flag = 1, FIN flag = 1 or FIN flag = 1, ACK flag = 0 or SYN = ACK = FIN = RST = PSH = 0