Combating DDoS Attacks with Fair Rate Throttling

被引:5
作者
Nur, Abdullah Yasin [1 ]
机构
[1] Univ New Orleans, Dept Comp Sci, New Orleans, LA 70148 USA
来源
2021 15TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON 2021) | 2021年
关键词
DoS; DDoS; Rate Adjustment; Router Throttle;
D O I
10.1109/SysCon48628.2021.9447054
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks are among the most harmful cyberattack types in the Internet. The main goal of a DDoS defense mechanism is to reduce the attack's effect as close as possible to their sources to prevent malicious traffic in the Internet. In this work, we examine the DDoS attacks as a rate management and congestion control problem and propose a collaborative fair rate throttling mechanism to combat DDoS attacks. Additionally, we propose anomaly detection mechanisms to detect attacks at the victim site, early attack detection mechanisms by intermediate Autonomous Systems (ASes), and feedback mechanisms between ASes to achieve distributed defense against DDoS attacks. To reduce additional vulnerabilities for the feedback mechanism, we use a secure, private, and authenticated communication channel between AS monitors to control the process. Our mathematical model presents proactive resource management, where the victim site sends rate adjustment requests to upstream routers. We conducted several experiments using a real-world dataset to demonstrate the efficiency of our approach under DDoS attacks. Our results show that the proposed method can significantly reduce the impact of DDoS attacks with minimal overhead to routers. Moreover, the proposed anomaly detection techniques can help ASes to detect possible attacks and early attack detection by intermediate ASes.
引用
收藏
页数:8
相关论文
共 22 条
  • [1] [Anonymous], Routeviews prefix to as mappings dataset (pfx2as) for ipv4 and ipv6
  • [2] [Anonymous], **DATA OBJECT**, DOI 10.23721/107/1354205
  • [3] [Anonymous], Computing TCP's Retransmission Timers (RFC)
  • [4] Chandrasekaran Balakrishnan., 2009, Survey of network traffic models, P567
  • [5] Gil TM, 2001, USENIX ASSOCIATION PROCEEDINGS OF THE 10TH USENIX SECURITY SYMPOSIUM, P23
  • [6] Jin C., 2000, Inet: Internet topology generator
  • [7] Levy N., 2017, NANOG
  • [8] Controlling high bandwidth aggregates in the network
    Mahajan, R
    Bellovin, SM
    Floyd, S
    Ioannidis, J
    Paxson, V
    Shenker, S
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2002, 32 (03) : 62 - 73
  • [9] Malialis K., 2015, ENG APPL ARTIF INTEL
  • [10] Nur A. Y., 2016, IEEE SMARTCOMP