首页> 外文会议>IEEE Network Operations and Management Symposium >High Performance Distributed Denial-of-Service Resilient Web Cluster Architecture
【24h】

High Performance Distributed Denial-of-Service Resilient Web Cluster Architecture

机译:高性能分布式拒绝服务弹性Web集群架构

获取原文

摘要

Though the WWW has come a long way since when it was monikered the World Wide Wait, it is still not reliable during heavy workload conditions. Overloads due to sudden arrival of users (flash crowds) is known to exponentially increase download times. More recently, online banks and portals have been the target of Distributed Denial-of-Service (DDoS) attacks, which send a deluge of requests and drive away the legitimate users. These overloads pose a new set of challenges towards efficient operation at enterprises that host web content which this dissertation addresses by combining knowledge of the network as well as server performance. In particular, this dissertation [1] proposes a web hosting architecture consisting of a grid of clusters, to provide high-performance in the presence of standard overload conditions as well as resilience during attacks. The architecture's high-performance component is provided by a server selection framework which selects the "best server" to serve a request as well as allows for an efficient multiplexing of resources across the entire cluster grid. Traditional approaches assume that minimizing network hop count minimizes client latency. In contrast, the proposed mechanism for server selection collects fine-grained server load and network latency measurements and forwards requests to the server that minimizes the total of estimated network and server delays. The architecture's DDoS-resilience is provided via a combination of anomaly detection and scheduling based mitigation of DDoS attacks. In contrast to prior work, the suspicion mechanism assigns a continuous valued vs. binary suspicion measure to each client session, and the scheduler utilizes these values to determine if and when to schedule a session's requests. Via a combination of analytical modeling and testbed experiments over an online bookstore implementation, the performance benefits achieved by the proposed cluster architecture are justified.
机译:虽然WWW以来,虽然当世界宽阔的等待时,但在繁重的工作量条件下仍然不可靠。已知由于用户突然到达(闪存人群)的过载是指数增长的下载时间。最近,在线银行和门户网站一直是分布式拒绝服务(DDOS)攻击的目标,该攻击发送了卓越的请求并驱动了合法用户。这些过载构成了在托管网络内容的企业中有效运行的新挑战,通过将网络知识以及服务器性能结合起来,托管网络内容。特别是,本论文[1]提出了由集群网格组成的网络托管架构,在存在标准过载条件以及攻击期间的弹性方面提供高性能。该架构的高性能组件由服务器选择框架提供,该框架选择“最佳服务器”以提供请求,并允许在整个群集网格上有效地多路复用资源。传统方法假设最小化网络跳数最小化客户端延迟。相比之下,所提出的服务器选择机制收集细粒度的服务器负载和网络延迟测量,并将请求转发给服务器,最小化估计的网络和服务器延迟的总数。通过对DDOS攻击的异常检测和调度的组合提供了架构的DDOS恢复力。与事先工作相比,疑似机制为每个客户端会话分配了连续值的与二进制疑似测量值,并且调度程序利用这些值来确定是否以及何时计划会话的请求。通过分析建模和测试平台实验结合在在线书店实现中,所提出的群集架构实现的性能效益是合理的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号