【24h】

Backward traffic throttling to mitigate bandwidth floods

机译:向后限制流量以减轻带宽泛滥

获取原文

摘要

We present Backward Traffic Throttling (BTT), an efficient, decentralized mechanism for congestion and bandwidth-flooding attacks mitigation. Upon congestion, BTT employs three basic mechanisms to throttle excessive traffic, namely: prioritize legitimate flows, shape traffic, and request upstream BTT nodes to similarly prioritize and shape traffic. Flow prioritizing parameters are determined independently by each BTT server, based on typical traffic estimations. BTT is easily deployed: it requires no changes to routers, and does not modify traffic. Instead, BTT configures routers' queuing discipline and traffic shapers. Both simulation and testbed experiments were performed to asses the effectiveness of BTT during distributed denial-of-service (DDoS) attacks. Results show that even limited BTT deployment alleviates attacks damage and allows legitimate TCP traffic to sustain communication, whereas larger deployments maintain larger portions of the original bandwidth.
机译:我们介绍了向后流量限制(BTT),一种有效的分散式机制,可缓解拥塞和带宽泛滥攻击。在拥塞时,BTT采用三种基本机制来抑制过多的流量,即:对合法流进行优先级划分,调整流量并请求上游BTT节点对流量进行优先级划分和调整。流量优先级参数由每个BTT服务器根据典型的流量估算独立确定。 BTT易于部署:它不需要更改路由器,也不需要修改流量。相反,BTT配置路由器的排队规则和流量整形器。进行了模拟和测试实验,以评估分布式拒绝服务(DDoS)攻击期间BTT的有效性。结果表明,即使有限的BTT部署也可以减轻攻击破坏,并允许合法的TCP流量维持通信,而较大的部署则保留了原始带宽的较大部分。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号