首页> 外文期刊>Computer networks >Preventing DDoS attacks on internet servers exploiting P2P systems
【24h】

Preventing DDoS attacks on internet servers exploiting P2P systems

机译:防止利用P2P系统的Internet服务器上的DDoS攻击

获取原文
获取原文并翻译 | 示例

摘要

Recently, there has been a spurt of work [1-7] showing that a variety of extensively deployed P2P systems may be exploited to launch DDoS attacks on web and other Internet servers, external to the P2P system. In this paper, we dissect these attacks and categorize them based on the underlying cause for attack amplification. We show that the attacks stem from a violation of three key principles: (ⅰ) membership information must be validated before use; (ⅱ) innocent participants must only propagate validated information; and (ⅲ) the system must protect against multiple references to the victim. We systematically explore the effectiveness of an active probing approach to validating membership information in thwarting such DDoS attacks. The approach does not rely on centralized authorities for membership verification, and is applicable to both structured (DHT-based) and unstructured P2P systems. We believe these considerations are important to ensure the mechanisms can be integrated with a range of existing P2P deployments. We evaluate the techniques in the context of a widely deployed DHT-based file-sharing system, and a video broadcasting system with stringent performance requirements. Our results show the promise of the approach in limiting DDoS attacks while not sacrificing application performance.
机译:近来,涌现的工作[1-7]表明,可以利用各种广泛部署的P2P系统在Web和其他Internet服务器(P2P系统外部)上发起DDoS攻击。在本文中,我们剖析了这些攻击,并根据造成攻击放大的根本原因对其进行了分类。我们证明,这些攻击源自违反三个关键原则:(ⅰ)会员信息在使用前必须经过验证; (ⅱ)无辜的参与者只能传播经过验证的信息; (ⅲ)系统必须防止对受害者的多次提及。我们系统地探索了一种主动探测方法来验证会员信息,从而有效地阻止了此类DDoS攻击。该方法不依赖中央机构进行成员身份验证,并且适用于结构化(基于DHT的)和非结构化P2P系统。我们认为,这些注意事项对于确保机制可以与一系列现有P2P部署集成在一起非常重要。我们在广泛部署的基于DHT的文件共享系统和具有严格性能要求的视频广播系统的背景下评估这些技术。我们的结果表明,该方法有望在不牺牲应用程序性能的情况下限制DDoS攻击。

著录项

  • 来源
    《Computer networks》 |2010年第15期|p.2756-2774|共19页
  • 作者单位

    School of Electrical and Computer Engineering, Purdue University. 465 Northwestern Avenue, West Lafayette, IN 47907, United States;

    School of Electrical and Computer Engineering, Purdue University. 465 Northwestern Avenue, West Lafayette, IN 47907, United States;

    School of Electrical and Computer Engineering, Purdue University. 465 Northwestern Avenue, West Lafayette, IN 47907, United States;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    P2P; DDoS; membership validation; experimental evaluation;

    机译:P2P;DDoS;成员资格验证;实验评估;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号