Scalable Network-Layer Defense Against Internet Bandwidth-Flooding Attacks

被引:39
|
作者
Argyraki, Katerina [1 ]
Cheriton, David R. [2 ]
机构
[1] Ecole Polytech Fed Lausanne, Sch Comp & Commun Sci, CH-1015 Lausanne, Switzerland
[2] Stanford Univ, Dept Comp Sci, Stanford, CA 94305 USA
关键词
Denial-of-service defenses; network-level security and protection; traffic filtering;
D O I
10.1109/TNET.2008.2007431
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In a bandwidth-flooding attack, compromised sources send high-volume traffic to the target with the purpose of causing congestion in its tail circuit and disrupting its legitimate communications. In this paper, we present Active Internet Traffic Filtering (AITF), a network-layer defense mechanism against such attacks. AITF enables a receiver to contact misbehaving sources and ask them to stop sending it traffic; each source that has been asked to stop is policed by its own Internet service provider (ISP), which ensures its compliance. An ISP that hosts misbehaving sources either supports AITF ( and accepts to police its misbehaving clients), or risks losing all access to the complaining receiver-this is a strong incentive to cooperate, especially when the receiver is a popular public-access site. We show that AITF preserves a significant fraction of a receiver's bandwidth in the face of bandwidth flooding, and does so at a per-client cost that is already affordable for today's ISPs; this per-client cost is not expected to increase, as long as botnet-size growth does not outpace Moore's law. We also show that even the first two networks that deploy AITF can maintain their connectivity to each other in the face of bandwidth flooding. We conclude that the network-layer of the Internet can provide an effective, scalable, and incrementally deployable solution against bandwidth-flooding attacks.
引用
收藏
页码:1284 / 1297
页数:14
相关论文
共 50 条
  • [1] Joint application and network defense against DDoS flooding attacks in the future Internet
    Karrer, Roger P.
    Kuehn, Ulrich
    Huehn, Thomas
    FGCN: PROCEEDINGS OF THE 2008 SECOND INTERNATIONAL CONFERENCE ON FUTURE GENERATION COMMUNICATION AND NETWORKING, VOLS 1 AND 2, 2008, : 9 - +
  • [2] Defense against flooding attacks using probabilistic thresholds in the internet of things ecosystem
    Zarei, Seyed Meysam
    Fotohi, Reza
    SECURITY AND PRIVACY, 2021, 4 (03)
  • [3] Network-layer Protection Schemes against Stealth Attacks on State Estimators in Power Systems
    Vukovic, Ognjen
    Sou, Kin Cheong
    Dan, Gyorgy
    Sandberg, Henrik
    2011 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2011,
  • [4] To filter or to authorize: Network-layer DoS Defense against multimillion-node botnets
    Liu, Xin
    Yang, Xiaowei
    Lu, Yanbin
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (04) : 195 - 206
  • [5] Novel Defense Mechanism against Data Flooding Attacks in Ad Hoc Network
    Bahaddur, Indira
    Triveni, C. L.
    Srikanth, P. C.
    2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [6] Software defined network moving target defense mechanism against link flooding attacks
    Xie L.
    Ding Y.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 36 - 43
  • [7] LOT: A Defense Against IP Spoofing and Flooding Attacks
    Gilad, Yossi
    Herzberg, Amir
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2012, 15 (02)
  • [8] Network-layer security for the Internet of Things using TinyOS and BLIP
    Granjal, Jorge
    Monteiro, Edmundo
    Silva, Jorge Sa
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (10) : 1938 - 1963
  • [9] A Network-Layer Proxy for Bandwidth Aggregation and Reduction of IP Packet Reordering
    Evensen, Kristian
    Kaspar, Dominik
    Engelstad, Paal
    Hansen, Audun F.
    Griwodz, Carsten
    Halvorsen, Pal
    2009 IEEE 34TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2009), 2009, : 585 - 592
  • [10] Defending against Flooding Attacks in the Internet of Drones Environment
    Pu, Cong
    Zhu, Pingping
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,