首页> 外文期刊>Computer networks >Improving the resilience of content distribution networks to large scale distributed denial of service attacks
【24h】

Improving the resilience of content distribution networks to large scale distributed denial of service attacks

机译:提高内容分发网络对大规模分布式拒绝服务攻击的弹性

获取原文
获取原文并翻译 | 示例

摘要

Distributed Denial of Service (DDoS) attacks remain a daunting challenge for Internet service providers. Previous work on countering these attacks has focused primarily on attacks at a single server location and the associated network infrastructure. Increasingly, however, high-volume sites are served via content distribution networks (CDNs). In this paper, we propose two mechanisms to withstand and deter DDoS attacks on CDN-hosted Web sites and the CDN infrastructure. First, we present a novel CDN request routing algorithm which allows CDN proxies to effectively distinguish attacks from the requests from actual users. The proposed scheme, based on the keyed hash function, can significantly improve the resilience of CDNs to DDoS attacks. In particular, the resilience of a CDN, consisting of n proxies, becomes O(n~2) with the proposed approach, when compared to a site hosted by a single server. We present performance numbers from a controlled test environment to show that the proposed approach is effective. Second, we introduce novel site allocation algorithms based on the well-established theory on binary codes. The proposed allocation algorithm guarantees an upper bound on the level of service outage of a CDN-hosted site even when a DoS attack on another site on the same CDN has been successful. Together, our schemes significantly improve the resilience of the Web sites hosted by CDNs, and complement other work on countering DoS.
机译:对于Internet服务提供商而言,分布式拒绝服务(DDoS)攻击仍然是艰巨的挑战。先前针对这些攻击的工作主要集中在针对单个服务器位置和相关网络基础结构的攻击。但是,越来越多的网站通过内容分发网络(CDN)提供服务。在本文中,我们提出了两种机制来抵制和阻止对CDN托管的网站和CDN基础结构的DDoS攻击。首先,我们提出了一种新颖的CDN请求路由算法,该算法使CDN代理可以有效地区分来自实际用户的攻击。所提出的方案基于键控哈希函数,可以显着提高CDN对DDoS攻击的恢复能力。尤其是,与单个服务器托管的站点相比,使用建议的方法,由n个代理组成的CDN的弹性变为O(n〜2)。我们从受控的测试环境中提供性能数字,以表明所提出的方法是有效的。其次,我们介绍基于完善的二进制代码理论的新颖站点分配算法。所提出的分配算法即使在同一CDN上对另一个站点的DoS攻击成功的情况下,也可以保证CDN托管站点的服务中断级别的上限。总之,我们的方案可以显着提高CDN托管的网站的弹性,并补充其他针对DoS的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号