首页> 外文会议>Conference on Computer Communications >Live Baiting for Service-Level DoS Attackers
【24h】

Live Baiting for Service-Level DoS Attackers

机译:服务级别DOS攻击者的实时诱饵

获取原文

摘要

Denial-of-Service (DoS) attacks remain a challenging problem in the Internet. By making resources unavailable to intended legitimate clients, DoS attacks have resulted in significant loss of time and money for many organizations, thus, many DoS defense mechanisms have been proposed. In this paper we propose live baiting, a novel approach for detecting the identities of DoS attackers. Live baiting leverages group-testing theory, which aims at discovering defective members in a population using the minimum number of "tests". This leverage allows live baiting to detect attackers using low state overhead without requiring models of legitimate requests nor anomalous behavior. The amount of state needed by live baiting is in the order of number of attackers not number of clients. This saving allows live baiting to scale to large services with millions of clients. We analyzed the coverage, effectiveness (detection time, false positive and false negative probabilities), and efficiency (memory, message overhead, and computational complexity) of our approach. We validated our analysis using NS-2 simulations modeled after real Web traces.
机译:拒绝服务(DOS)攻击仍然是互联网上有挑战性的问题。通过为预期合法客户提供资源,对于许多组织而言,DOS攻击导致了大量的时间和金钱,因此,已经提出了许多DOS防御机制。在本文中,我们提出了Live诱饵,一种检测DOS攻击者身份的新方法。实时诱饵利用小组测试理论,旨在使用最小“测试”的人口中发现有缺陷的成员。这种杠杆允许实时诱饵检测使用低状态开销的攻击者,而无需特殊请求的模型,也不需要异常行为。现场诱饵所需的国家数量是攻击者数量的数量,而不是客户的数量。这种拯救允许Live诱饵与数百万客户的大型服务缩放。我们分析了我们方法的覆盖范围,有效性(检测时间,假正负概率),以及效率(内存,消息开销和计算复杂性)。我们使用Real Web Trave后建模的NS-2模拟验证了我们的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号