...
首页> 外文期刊>Computer Communications >Net-Police: A network patrolling service for effective mitigation of volumetric DDoS attacks
【24h】

Net-Police: A network patrolling service for effective mitigation of volumetric DDoS attacks

机译:净警察:用于有效缓解体积DDOS攻击的网络巡逻服务

获取原文
获取原文并翻译 | 示例

摘要

Volumetric Distributed Denial of Service (DDoS) attacks are a significant concern for information technology-based organizations. These attacks result in significant revenue losses in terms of wastage of resources and unavailability of services at the victim (e.g., business websites, DNS servers, etc.) as well as the Internet Service Providers (ISPs) along the path of the attack. The state-of-the-art DDoS mitigation mechanisms attempt to alleviate the losses at either the victim or the ISPs, but not both. In this paper, we present Net-Police, which is a traffic patrolling system for DDoS mitigation. Net-Police identifies the sources of attack so that filters can be employed at these sources in order to quickly mitigate the attack. Such a solution effectively prevents the flow of malicious traffic across the ISP networks, thereby benefiting the ISPs also. Net-Police patrols the network by designating a small number of routers as dynamic packet taggers, to prune benign regions in the network, and localize the search to the Autonomous Systems (AS) from which the attack originates. We evaluate the proposed solution on 257 real-world topologies from the Internet Topology Zoo library and the Internet AS level topology. The paper also presents details of our hardware test-bed platform consisting of 30 routers on which network services such as Net-Police can be implemented and studied for on-field feasibility. Our experiments reveal that Net-Police performs better than the state-of-the-art cloud-based and traceback-based solutions in terms of ISP bandwidth savings and availability of the victim to legitimate clients.
机译:体积分布式拒绝服务(DDOS)攻击是基于信息技术的组织的重要关注。这些攻击在受害者的资源浪费和不可用的情况下产生了重大收入损失(例如,商业网站,DNS服务器等)以及沿着攻击路径的互联网服务提供商(ISP)。最先进的DDOS缓解机制试图减轻受害者或ISP的损失,而不是两者。在本文中,我们提出了净警察,这是一个用于DDOS缓解的流量巡逻系统。净警察确定攻击来源,以便在这些来源中使用过滤器,以便快速减轻攻击。这种解决方案有效地防止了ISP网络中的恶意流量流动,从而使ISPS受益。 Net-Porket通过将少量路由器作为动态数据包标签指定为网络,并将攻击源自攻击的自治系统(AS)本地化搜索,本地化了良好的路由器来巡逻网络。我们在互联网拓扑动物图书馆和互联网中评估了257个现实世界拓扑的建议解决方案作为级别拓扑。本文还介绍了我们的硬件测试床平台的详细信息,包括30个路由器,可在哪些网络服务,如净警察等领域的可行性。我们的实验表明,在ISP带宽节省和受害者的可用性方面,Net-POST比基于最先进的云和基于追溯的解决方案更好。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号