首页> 外文会议>International Conference on Networking and Mobile Computing >HAWK: Halting Anomalies with Weighted Choking to Rescue Weil-Behaved TCP Sessions from Shrew DDoS Attacks
【24h】

HAWK: Halting Anomalies with Weighted Choking to Rescue Weil-Behaved TCP Sessions from Shrew DDoS Attacks

机译:Hawk:通过加权窒息停止异常,从Shrew DDOS攻击中拯救威尔表现的TCP会话

获取原文

摘要

High availability in network services is crucial for effective large-scale distributed computing. While distributed denial-of-service (DDoS) attacks through massive packet flooding have baffled researchers for years, a new type of even more detrimental attack—shrew attacks (periodic intensive packet bursts with low average rate)—has recently been identified. Shrew attacks can significantly degrade well-behaved TCP sessions, repel potential new connections, and are very difficult to detect, not to mention defend against, due to its low average rate. We propose a new stateful adaptive queue management technique called HAWK (Halting Anomaly with Weighted choKing) which works by judiciously identifying malicious shrew packet flows using a small flow table and dropping such packets decisively to halt the attack such that well-behaved TCP sessions can re-gain their bandwidth shares. Our NS-2 based extensive performance results indicate that HAWK is highly agile.
机译:网络服务中的高可用性对于有效的大规模分布式计算至关重要。虽然通过大规模包洪水分布式拒绝服务(DDOS)攻击多年来,但多年来,新型甚至更有害的攻击攻击攻击(最近的平均速率的周期性密集型数据包爆发) - 最近被识别出来。 Shrew攻击可以显着降低表现良好的TCP会话,击退潜在的新连接,并且由于其平均速度低,难以检测,更难检测,更难以提及防御。我们提出了一种称为Hawk(暂停异常具有加权窒息的异常)的新的有状态自适应队列管理技术,这通过谨慎地识别恶意挑例,使用小流动表并落实果断地丢弃这种数据包来停止攻击,使得表现良好的TCP会话可以重新 - 他们的带宽股。我们的NS-2基于的广泛表现结果表明,鹰是高度敏捷的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号