This document proposes a Controller-Agent model to minimize distributed denial of service (DDoS) attacks on the Internet. The model identifies attacks at the victim and prevents them near the attacking source. It uses a new packet marking technique and agent design to identify the approximate source of an attack with a single packet, even with spoofed source addresses. The model only operates during attacks, processes victim traffic separately without disrupting other traffic, and can quickly respond to changes in attack traffic patterns. The authors believe this approach provides an effective and practical way to counteract DDoS attacks.