Off The Wall: Lightweight Distributed Filtering to Mitigate Distributed Denial of Service Attacks

被引:3
作者
Fu, Zhang [1 ]
Papatriantafilou, Marina [1 ]
机构
[1] Chalmers Univ Technol, S-42196 Gothenburg, Sweden
来源
2012 31ST INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS 2012) | 2012年
关键词
D O I
10.1109/SRDS.2012.45
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks are hard to deal with, due to the fact that it is difficult to distinguish legitimate traffic from malicious traffic, especially since the latter is from distributed sources. To accurately filter malicious traffic one needs (strong but costly) packet authentication primitives which increase the design complexity and typically affect throughput. It is a challenge to keep a balance between throughput and security/protection of the network core and end resources. In this paper, we propose SIEVE, a lightweight distributed filtering protocol/method. Depending on the attacker's ability, SIEVE can provide a standalone filter for moderate adversary models and a complementary filter which can enhance the performance of strong and more complex methods for stronger adversary models.
引用
收藏
页码:207 / 212
页数:6
相关论文
共 19 条
  • [1] Andersen D.G., 2003, USITS'03: Proceedings of the 4th conference on USENIX Symposium on Internet Technologies and Systems, P3
  • [2] [Anonymous], 2008, BOTMINER CLUSTERING
  • [3] Badishi G, 2007, IEEE T DEPEND SECURE, V4, P191, DOI [10.1109/TDSC.2007.70209, 10.1109/TDSC.2007.70209.]
  • [4] Broder Andrei, 2002, Internet mathematics, P636, DOI DOI 10.1080/15427951.2004.10129096
  • [5] Dixon C., 2008, NSDI'08: Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation, P45
  • [6] Faloutsos M, 1999, COMP COMM R, V29, P251, DOI 10.1145/316194.316229
  • [7] Fu Z., 2011, 201120 CHALM U TECHN
  • [8] Fu Z., 2008, SRDS 08
  • [9] Hussain A, 2003, ACM SIGCOMM COMP COM, V33, P99
  • [10] SOS: Secure Overlay Services
    Keromytis, AD
    Misra, V
    Rubenstein, D
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2002, 32 (04) : 61 - 72