首页> 外文期刊>Networking, IEEE/ACM Transactions on >DDoS-Shield: DDoS-Resilient Scheduling to Counter Application Layer Attacks
【24h】

DDoS-Shield: DDoS-Resilient Scheduling to Counter Application Layer Attacks

机译:DDoS防护:DDoS弹性调度以应对应用程序层攻击

获取原文
获取原文并翻译 | 示例

摘要

Countering distributed denial of service (DDoS) attacks is becoming ever more challenging with the vast resources and techniques increasingly available to attackers. In this paper, we consider sophisticated attacks that are protocol-compliant, non-intrusive, and utilize legitimate application-layer requests to overwhelm system resources. We characterize application-layer resource attacks as either request flooding, asymmetric, or repeated one-shot, on the basis of the application workload parameters that they exploit. To protect servers from these attacks, we propose a counter-mechanism namely DDoS Shield that consists of a suspicion assignment mechanism and a DDoS-resilient scheduler. In contrast to prior work, our suspicion mechanism assigns a continuous value as opposed to a binary measure to each client session, and the scheduler utilizes these values to determine if and when to schedule a session's requests. Using testbed experiments on a web application, we demonstrate the potency of these resource attacks and evaluate the efficacy of our counter-mechanism. For instance, we mount an asymmetric attack which overwhelms the server resources, increasing the response time of legitimate clients from 0.3 seconds to 40 seconds. Under the same attack scenario, DDoS Shield improves the victims' performance to 1.5 seconds.
机译:随着攻击者越来越多地使用大量资源和技术,应对分布式拒绝服务(DDoS)攻击变得越来越具有挑战性。在本文中,我们考虑了符合协议,非侵入性的复杂攻击,并利用合法的应用程序层请求来淹没系统资源。根据应用程序层资源利用的应用程序工作负载参数,我们将应用程序层资源攻击的特征描述为请求泛洪,不对称或重复一次。为了保护服务器免受这些攻击,我们提出了一种反机制,即DDoS Shield,它由可疑分配机制和DDoS弹性调度程序组成。与以前的工作相比,我们的怀疑机制为每个客户端会话分配了一个与二进制度量相反的连续值,并且调度程序利用这些值来确定是否以及何时调度会话的请求。使用Web应用程序上的测试平台实验,我们演示了这些资源攻击的效力,并评估了对抗机制的功效。例如,我们发动了一次非对称攻击,使服务器资源不堪重负,合法客户端的响应时间从0.3秒增加到40秒。在相同的攻击情形下,DDoS Shield可以将受害者的性能提高到1.5秒。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号