CoDef: Collaborative Defense Against Large-Scale Link-Flooding Attacks

被引:68
作者
Lee, Soo Bum [1 ]
Kang, Min Suk [2 ]
Gligor, Virgil D. [2 ]
机构
[1] Qualcomm, San Diego, CA USA
[2] Carnegie Mellon Univ, ECE & CyLab, Pittsburgh, PA 15213 USA
来源
PROCEEDINGS OF THE 2013 ACM INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT '13) | 2013年
关键词
DDoS defense; collaborative defense; link-flooding attack; rerouting; bandwidth guarantees;
D O I
10.1145/2535372.2535398
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Large-scale botnet attacks against Internet links using low-rate flows cannot be effectively countered by any of the traditional rate-limiting and flow-filtering mechanisms deployed in individual routers. In this paper, we present a collaborative defense mechanism, called CoDef, which enables routers to distinguish low-rate attack flows from legitimate flows, and protect legitimate traffic during botnet attacks. CoDef enables autonomous domains that are uncontaminated by bots to collaborate during link flooding attacks and reroute their customers' legitimate traffic in response to requests from congested routers. Collaborative defense using multi-path routing favors legitimate traffic while limiting the bandwidth available to attack traffic at a congested link We present CoDef's design and evaluate its effectiveness by exploring the domain-level path diversity of the Internet and performing simulations under various traffic conditions.
引用
收藏
页码:417 / 427
页数:11
相关论文
共 31 条
[1]  
Andersen D.G., 2008, P ACM SIGCOMM SEATTL
[2]  
Andersen David., 2001, SOSP 01
[3]  
[Anonymous], 2001, 3031 RFC
[4]  
[Anonymous], P IEEE S SEC PRIV
[5]  
Arbor Networks, 2012, WHIT DDOS ATT TOOLS
[6]  
Argyraki K., FDNA 04
[7]  
Argyraki Katerina, ATEC 05
[8]  
Cao J., 2004, INFOCOMM
[9]  
Casado M., 2012, P HOTSDN ACM
[10]  
Cisco, 2012, 13753 CISC