首页> 外文会议>IEEE Conference on Local Computer Networks >An SDN-based Approach For Defending Against Reflective DDoS Attacks
【24h】

An SDN-based Approach For Defending Against Reflective DDoS Attacks

机译:基于SDN的反射DDoS攻击防御方法

获取原文

摘要

Distributed Reflective Denial of Service (DRDoS) attacks are an immanent threat to Internet services. The potential scale of such attacks became apparent in March 2018 when a memcached-based attack peaked at 1.7 Tbps. Novel services built upon UDP increase the need for automated mitigation mechanisms that react to attacks without prior knowledge of the actual application protocols used. With the flexibility that software-defined networks offer, we developed a new approach for defending against DRDoS attacks; it not only protects against arbitrary DRDoS attacks but is also transparent for the attack target and can be used without assistance of the target host operator. The approach provides a robust mitigation system which is protocol-agnostic and effective in the defense against DRDoS attacks.
机译:分布式反射式拒绝服务(DRDoS)攻击是对Internet服务的固有威胁。这种攻击的潜在规模在2018年3月变得明显,当时基于内存缓存的攻击达到1.7 Tbps的峰值。基于UDP的新型服务增加了对自动缓解机制的需求,这些机制无需事先了解所使用的实际应用协议即可对攻击做出反应。借助软件定义网络提供的灵活性,我们开发了一种新的防御DRDoS攻击的方法。它不仅可以防御任意的DRDoS攻击,而且对攻击目标是透明的,并且无需目标主机操作员的帮助即可使用。该方法提供了一个健壮的缓解系统,该系统与协议无关,可有效防御DRDoS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号