首页> 外文会议>International Parallel and Distributed Processing Symposium >Adaptive Distributed Traffic Control Service for DDoS Attack Mitigation
【24h】

Adaptive Distributed Traffic Control Service for DDoS Attack Mitigation

机译:DDOS攻击缓解的自适应分布式流量控制服务

获取原文

摘要

Frequency and intensity of Internet attacks are rising with an alarming pace. Several technologies and concepts were proposed for fighting distributed denial of service (DDoS) attacks: traceback, pushback, i3, SOS and Mayday. This paper shows that in the case of DDoS reflector attacks they are either ineffective or even counterproductive. We then propose a novel concept and system that extends the control over network traffic by network users to the Internet using adaptive traffic processing devices. We safely delegate partial network management capabilities from network operators to network users. All network packets with a source or destination address owned by a network user can now also be controlled within the Internet instead of only at the network user's Internet uplink. By limiting the traffic control features and by restricting the realm of control to the "owner" of the traffic, we can rule out misuse of this system. Applications of our system are manifold: prevention of source address spoofing, DDoS attack mitigation, distributed firewall-like filtering, new ways of collecting traffic statistics, traceback, distributed network debugging, support for forensic analyses and many more.
机译:频率和互联网的攻击强度与惊人的速度上升。一些技术和理念,提出了战斗的服务(DDoS)分布式拒绝服务攻击:回溯,回推,I3,SOS和五月天。本文表明,在反射器的DDoS攻击的情况下,它们是无效甚至适得其反。然后,我们建议,扩展了网络用户使用自适应流量处理设备在互联网上的网络流量控制一个新颖的概念和系统。我们安全地委派从网络运营商向网络用户部分网络管理功能。与网络用户所拥有的源或目的地址的所有网络数据包,现在也可以在Internet中,而不是只在网络用户的互联网上行来控制。通过限制流量控制功能,并通过限制控制到交通的“所有者”的境界,我们可以排除该系统的滥用。我们的系统的应用是多方面的:防止源地址欺骗,DDoS攻击缓解,分布式的类似防火墙的过滤,新的流量统计,回溯的方式,分布式网络调试,法医分析和更多的支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号