首页> 外文会议>IEEE Symposium on Security and Privacy >Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP Routing
【24h】

Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP Routing

机译:围绕拥塞进行路由:通过反应性BGP路由来防御DDoS攻击和不利的网络状况

获取原文

摘要

In this paper, we present Nyx, the first system to both effectively mitigate modern Distributed Denial of Service (DDoS) attacks regardless of the amount of traffic under adversarial control and function without outside cooperation or an Internet redesign. Nyx approaches the problem of DDoS mitigation as a routing problem rather than a filtering problem. This conceptual shift allows Nyx to avoid many of the common shortcomings of existing academic and commercial DDoS mitigation systems. By leveraging how Autonomous Systems (ASes) handle route advertisement in the existing Border Gateway Protocol (BGP), Nyx allows the deploying AS to achieve isolation of traffic from a critical upstream AS off of attacked links and onto alternative, uncongested, paths. This isolation removes the need for filtering or de-prioritizing attack traffic. Nyx controls outbound paths through normal BGP path selection, while return paths from critical ASes are controlled through the use of specific techniques we developed using existing traffic engineering principles and require no outside coordination. Using our own realistic Internet-scale simulator, we find that in more than 98% of cases our system can successfully route critical traffic around network segments under transit-link DDoS attacks; a new form of DDoS attack where the attack traffic never reaches the victim AS, thus invaliding defensive filtering, throttling, or prioritization strategies. More significantly, in over 95% of those cases, the alternate path provides complete congestion relief from transit-link DDoS. Nyx additionally provides complete congestion relief in over 75% of cases when the deployer is being directly attacked.
机译:在本文中,我们介绍了Nyx,这是第一个可以有效缓解现代分布式拒绝服务(DDoS)攻击的系统,而无需考虑对手控制和功能下的流量大小,而无需外部合作或重新设计Internet。 Nyx将DDoS缓解问题作为路由问题而不是过滤问题来解决。这种概念上的转变使Nyx可以避免现有学术和商业DDoS缓解系统的许多常见缺点。通过利用自治系统(ASes)处理现有边界网关协议(BGP)中的路由通告的方式,Nyx允许部署中的AS隔离来自关键上游AS的流量,使其脱离受攻击的链路,并进入备选的,未拥塞的路径。这种隔离消除了对攻击流量进行过滤或取消优先级的需求。 Nyx通过正常的BGP路径选择来控制出站路径,而来自关键AS的返回路径则通过使用我们使用现有流量工程原理开发的特定技术进行控制,而无需外部协调。使用我们自己的逼真的Internet规模模拟器,我们发现在超过98%的情况下,我们的系统可以在传输链路DDoS攻击下成功地在网络段周围路由关键流量。一种新的DDoS攻击形式,攻击流量永远不会到达受害AS,从而使防御性过滤,限制或优先级策略无效。更重要的是,在超过95%的情况下,备用路径可从传输链路DDoS完全缓解拥塞。当部署者受到直接攻击时,Nyx还可以在超过75%的情况下提供完全的拥塞缓解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号