Methods and systems for thwarting denial of service attacks originating in
a DOCSIS-compliant cable network (DCN) are described. A DCN comprises one
or more sub-networks each comprising an access network, one or more cable
modem termination systems (CMTSs) and one or more cable modems (CMs). The
DCN also accesses an edge server and a local DNS cache server. The DCN
interfaces with the Internet and accesses a remote DNS server according
to well-known protocols. The CMTS is adapted to compare the source IP
address included in IP packet headers to the IP address of the customer
premises equipment (CPE) from which the IP packet originates as assigned
by the DNS. Data packets that have spoofed addresses are either deleted
or quarantined. Packets reaching the edge server are evaluated by an
attack detection system. A packet determined to be part of a denial of
service attack is inspected and the source IP address and the destination
IP address extracted. A cache controller is instructed to prevent a DNS
cache server from responding to a domain name request containing both the
extracted source IP address and destination IP address.