The document presents a distributed approach for defending web services against Distributed Denial of Service (DDoS) attacks, emphasizing its advantages over centralized methods. It discusses a framework leveraging traffic cluster entropy and source address entropy for early detection and filtering of attack traffic at multiple points on the internet. The authors argue that an ISP-based solution provides a practical and viable defense mechanism due to its resource availability and ability for cooperation in combatting DDoS threats.