首页> 外文会议>Information systems security >A Multilayer Overlay Network Architecture for Enhancing IP Services Availability against DoS
【24h】

A Multilayer Overlay Network Architecture for Enhancing IP Services Availability against DoS

机译:一种针对DoS增强IP服务可用性的多层覆盖网络体系结构

获取原文
获取原文并翻译 | 示例

摘要

Protection against Denial of Service (DoS) attacks is a chal lenging and ongoing problem. Current overlay-based solutions can trans parently filter unauthorized traffic based on user authentication. Such solutions require either pre-established trust or explicit user interaction to operate, which can be circumvented by determined attackers and is not always feasible (e.g., when user interaction is impossible or undesir able). We propose a Multi-layer Overlay Network (MON) architecture that does not depend on user authentication, but instead utilizes two mechanisms to provide DoS resistant to any IP-based service, and op erates on top of the existing network infrastructure. First, MON imple ments a threshold-based intrusion detection mechanism in a distributed fashion to mitigate DoS close to the attack source. Second, it randomly distributes user packets amongst different paths to probabilistically in crease service availability during an attack. We evaluate MON using the Apache web server as a protected service. Results demonstrate MON nodes introduce very small overhead, while users' service access time in creases by a factor of 1.1 to 1.7, depending on the configuration. Under an attack scenario MON can decrease the attack traffic forwarded to the service by up to 85%. We believe our work makes the use of overlays for DoS protection more practical relative to prior work.
机译:防范拒绝服务(DoS)攻击是一个艰巨而持续的问题。当前基于覆盖的解决方案可以基于用户身份验证从父级过滤未经授权的流量。这样的解决方案需要预先建立的信任或明确的用户交互来操作,这可以由确定的攻击者规避并且并不总是可行的(例如,当用户交互是不可能的或不希望的时)。我们提出了一种不依赖用户身份验证的多层覆盖网络(MON)架构,而是利用两种机制来提供对任何基于IP的服务的DoS防护,并在现有网络基础架构之上进行操作。首先,MON以分布式方式实现基于阈值的入侵检测机制,以缓解靠近攻击源的DoS。其次,它在不同路径之间随机分配用户数据包,以概率地提高攻击过程中的服务可用性。我们使用Apache Web服务器作为受保护的服务来评估MON。结果表明,MON节点的开销很小,而用户的服务访问时间则根据配置而增加了1.1到1.7倍。在攻击情形下,MON最多可以减少转发到服务的攻击流量的85%。我们相信,与以前的工作相比,我们的工作使对DoS保护的覆盖更加实用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号