【24h】

Backward traffic throttling to mitigate bandwidth floods

机译:向后流量节流以缓解带宽洪水

获取原文

摘要

We present Backward Traffic Throttling (BTT), an efficient, decentralized mechanism for congestion and bandwidth-flooding attacks mitigation. Upon congestion, BTT employs three basic mechanisms to throttle excessive traffic, namely: prioritize legitimate flows, shape traffic, and request upstream BTT nodes to similarly prioritize and shape traffic. Flow prioritizing parameters are determined independently by each BTT server, based on typical traffic estimations. BTT is easily deployed: it requires no changes to routers, and does not modify traffic. Instead, BTT configures routers' queuing discipline and traffic shapers. Both simulation and testbed experiments were performed to asses the effectiveness of BTT during distributed denial-of-service (DDoS) attacks. Results show that even limited BTT deployment alleviates attacks damage and allows legitimate TCP traffic to sustain communication, whereas larger deployments maintain larger portions of the original bandwidth.
机译:我们展示了向后交通流量(BTT),有效,分散机制的拥堵和带宽泛滥攻击缓解。 在拥塞后,BTT采用三种基本机制来节气门的流量,即:优先顺序合法流量,形状流量,以及上游BTT节点以类似优先顺序和形状流量。 基于典型的业务估计,每个BTT服务器独立地确定流程优先级参数。 BTT很容易部署:它不需要更改路由器,并且不修改流量。 相反,BTT配置路由器的排队纪律和流量整形者。 进行仿真和测试的实验,进行分布式拒绝服务(DDOS)攻击期间BTT的有效性。 结果表明,即使是Limited BTT部署减轻了攻击损坏,允许合法的TCP流量维持通信,而较大的部署则保持原始带宽的较大部分。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号