首页> 外文会议>IFIP Networking Conference >PathFinder: Capturing DDoS Traffic Footprints on the Internet
【24h】

PathFinder: Capturing DDoS Traffic Footprints on the Internet

机译:路径查找器:捕获Internet上的DDoS流​​量足迹

获取原文

摘要

While distributed denial-of-service (DDoS) attacks are easy to launch and are becoming more damaging, the defense against DDoS attacks often suffers from the lack of relevant knowledge of the DDoS traffic, including the paths the DDoS traffic has used, the source addresses (spoofed or not) that appear along each path, and the amount of traffic per path or per source. Though IP traceback and path inference approaches could be considered, they are either expensive and hard to deploy or inaccurate. We propose PathFinder, a service that a DDoS defense system can use to obtain the footprints of the DDoS traffic to the victim as is. It introduces a PFTrie data structure with multiple design features to log traffic at line rate, and is easy to implement and deploy on today's Internet. We show that PathFinder can significantly improve the efficacy of a DDoS defense system, while PathFinder itself is fast and has a manageable overhead.
机译:尽管分布式拒绝服务(DDoS)攻击易于发动且具有更大的破坏力,但针对DDoS攻击的防御通常会因缺乏有关DDoS流​​量的相关知识(包括DDoS流​​量已使用的路径,来源)而受苦沿每个路径出现的地址(是否经过欺骗),以及每个路径或每个源的流量。尽管可以考虑IP追溯和路径推断方法,但它们要么昂贵,要么难以部署或不准确。我们建议使用PathFinder,DDoS防御系统可以使用该服务按原样获取到达受害者的DDoS流​​量的足迹。它引入了具有多个设计功能的PFTrie数据结构,以线速记录流量,并且易于在当今的Internet上实现和部署。我们展示了PathFinder可以显着提高DDoS防御系统的效率,而PathFinder本身则是快速且开销可管理的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号