【24h】

New Client Puzzle Outsourcing Techniques for DoS Resistance

机译:新客户拼图外包技术的DOS抵抗

获取原文

摘要

We explore new techniques for the use of cryptographic puzzles as a countermeasure to Denial-of-Service (DoS) attacks. We propose simple new techniques that permit the outsourcing of puzzles-their distribution via a robust external service that we call a bastion. Many servers can rely on puzzles distributed by a single bastion. We show how a bastion, somewhat surprisingly, need not know which servers rely on its services. Indeed, in one of our constructions, a bastion may consist merely of a publicly accessible random data source, rather than a special purpose server. Our outsourcing techniques help eliminate puzzle distribution as a point of compromise. Our design has three main advantages over prior approaches. First, it is more resistant to DoS attacks aimed at the puzzle mechanism itself, withstanding over 80% more attack traffic than previous methods in our experiments. Second, our scheme is cheap enough to apply at the IP level, though it also works at higher levels of the protocol stack. Third, our method allows clients to solve puzzles offline, reducing the need for users to wait while their computers solve puzzles. We present a prototype implementation of our approach, and we describe experiments that validate our performance claims.
机译:我们探索使用密码拼图作为拒绝服务(DOS)攻击的对策。我们提出了简单的新技术,允许通过我们称之为堡垒的强大外部服务外包 - 他们的分发。许多服务器可以依赖于单一堡垒分发的谜题。我们展示了一个堡垒,有些令人惊讶的是,不必知道哪些服务器依赖其服务。实际上,在我们的一个结构中,堡垒可能仅包括可公开访问的随机数据源,而不是特殊用途服务器。我们的外包技术有助于消除拼图分布作为妥协的点。我们的设计与现有方法相比有三个主要优点。首先,它更耐受针对拼图机制本身的DOS攻击,超过我们实验中以前的方法超过80%的攻击交通。其次,我们的计划足够便宜,以便在IP级别申请,但它也适用于协议栈的更高级别。第三,我们的方法允许客户端离线解决难题,减少用户在其计算机解决难题时等待的需求。我们介绍了我们方法的原型实施,我们描述了验证我们的业绩索赔的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号