【24h】

Catch Me If You Can: A Cloud-Enabled DDoS Defense

机译:可以的话赶上我:启用云的DDoS防御

获取原文
获取原文并翻译 | 示例

摘要

We introduce a cloud-enabled defense mechanism for Internet services against network and computational Distributed Denial-of-Service (DDoS) attacks. Our approach performs selective server replication and intelligent client re-assignment, turning victim servers into moving targets for attack isolation. We introduce a novel system architecture that leverages a "shuffling" mechanism to compute the optimal re-assignment strategy for clients on attacked servers, effectively separating benign clients from even sophisticated adversaries that persistently follow the moving targets. We introduce a family of algorithms to optimize the runtime client-to-server re-assignment plans and minimize the number of shuffles to achieve attack mitigation. The proposed shuffling-based moving target mechanism enables effective attack containment using fewer resources than attack dilution strategies using pure server expansion. Our simulations and proof-of-concept prototype using Amazon EC2 [1] demonstrate that we can successfully mitigate large-scale DDoS attacks in a small number of shuffles, each of which incurs a few seconds of user-perceived latency.
机译:我们针对互联网服务引入了一种支持云的防御机制,以抵御网络和计算分布式拒绝服务(DDoS)攻击。我们的方法执行选择性服务器复制和智能客户端重新分配,将受害服务器转变为移动目标以进行攻击隔离。我们介绍了一种新颖的系统架构,该架构利用“改组”机制为受攻击的服务器上的客户端计算最佳的重新分配策略,从而有效地将良性客户端与始终遵循移动目标的复杂对手区分开。我们引入了一系列算法,以优化运行时客户端到服务器的重新分配计划,并最大程度地减少改组次数以实现缓解攻击的目的。与基于纯服务器扩展的攻击稀释策略相比,所提出的基于混洗的移动目标机制可以使用更少的资源实现有效的攻击遏制。我们使用Amazon EC2 [1]进行的仿真和概念验证原型表明,我们可以通过少量混洗成功缓解大规模DDoS攻击,每次混洗都会导致几秒钟的用户感知延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号