On Multi-Point, In-Network Filtering of Distributed Denial-of-Service Traffic

2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM)(2019)

引用 24|浏览34
暂无评分
摘要
Research has shown that distributed denial-of-service (DDoS) attacks on the Internet could often be better handled by enlisting the in-network defense of multiple autonomous systems (ASes), rather than relying entirely on the victim's Internet Service Provider at the edge. Less noticed but important is the fact that an in-network defense can also remove DDoS traffic from the Internet early en route to the victim, thus decreasing the overall load on the Internet and reducing chances of link congestion. However, it is not well understood to what degree different in-network defense strategies can achieve such benefits. In this paper, we model the existing two main categories of in-network DDoS defense algorithms (PushBack, SourceEnd) and propose a new type of algorithm (StrategicPoints). In particular, we compare their effectiveness in minimizing the amount of DDoS traffic that the victim receives, their impact on reducing the DDoS traffic on the entire Internet, and their resiliency against intelligent adversaries and dynamic attacks. We detail how the comparison results vary according to parameters and provide our insights on the pros and cons of these three categories of in-network DDoS defense solutions.
更多
查看译文
关键词
multiple autonomous systems,in-network DDoS defense algorithms,distributed denial-of-service,Internet,Internet service provider,link congestion,pushback algorithm,sourceend algorithm,strategicpoints algorithm
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要