【24h】

A DoS-limiting network architecture

机译:DOS限制网络架构

获取原文

摘要

We present the design and evaluation of TVA, a network architecture that limits the impact of Denial of Service (DoS) floods from the outset. Our work builds on earlier work on capabilities in which senders obtain short-term authorizations from receivers that they stamp on their packets. We address the full range of possible attacks against communication between pairs of hosts, including spoofed packet floods, network and host bottlenecks, and router state exhaustion. We use simulation to show that attack traffic can only degrade legitimate traffic to a limited extent, significantly outperforming previously proposed DoS solutions. We use a modified Linux kernel implementation to argue that our design can run on gigabit links using only inexpensive off-the-shelf hardware. Our design is also suitable for transition into practice, providing incremental benefit for incremental deployment.
机译:我们介绍了TVA的设计和评估,网络架构限制了从一开始就限制了拒绝服务(DOS)洪水的影响。我们的工作在早期的工作中构建了发件人从他们的数据包中盖章的接收者获取短期授权的功能。我们满足了对主机对之间的通信的全部攻击,包括欺骗数据包泛洪,网络和主机瓶颈以及路由器状态耗尽。我们使用模拟显示攻击流量只能降低合法的流量,有限的程度,显着优于先前提出的DOS解决方案。我们使用修改后的Linux内核实现来争辩说我们的设计可以在千兆链接上使用廉价的现成硬件运行。我们的设计也适合过渡到实践中,为增量部署提供增量益处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号