首页> 外文期刊>Networking, IEEE/ACM Transactions on >Scalable Network-Layer Defense Against Internet Bandwidth-Flooding Attacks
【24h】

Scalable Network-Layer Defense Against Internet Bandwidth-Flooding Attacks

机译:可扩展的网络层防御,以应对Internet带宽泛滥攻击

获取原文
获取原文并翻译 | 示例
       

摘要

In a bandwidth-flooding attack, compromised sources send high-volume traffic to the target with the purpose of causing congestion in its tail circuit and disrupting its legitimate communications. In this paper, we present Active Internet Traffic Filtering (AITF), a network-layer defense mechanism against such attacks. AITF enables a receiver to contact misbehaving sources and ask them to stop sending it traffic; each source that has been asked to stop is policed by its own Internet service provider (ISP), which ensures its compliance. An ISP that hosts misbehaving sources either supports AITF (and accepts to police its misbehaving clients), or risks losing all access to the complaining receiver—this is a strong incentive to cooperate, especially when the receiver is a popular public-access site. We show that AITF preserves a significant fraction of a receiver's bandwidth in the face of bandwidth flooding, and does so at a per-client cost that is already affordable for today's ISPs; this per-client cost is not expected to increase, as long as botnet-size growth does not outpace Moore's law. We also show that even the first two networks that deploy AITF can maintain their connectivity to each other in the face of bandwidth flooding. We conclude that the network-layer of the Internet can provide an effective, scalable, and incrementally deployable solution against bandwidth-flooding attacks.
机译:在带宽泛滥的攻击中,受感染的源将大量流量发送到目标,目的是导致其尾部电路拥塞并破坏其合法通信。在本文中,我们提出了主动Internet流量过滤(AITF),一种针对此类攻击的网络层防御机制。 AITF使接收方可以联系行为不正常的源,并要求他们停止向其发送流量;被要求停止的每个源均由其自己的Internet服务提供商(ISP)进行监管,以确保其合规性。托管来源不当的ISP要么支持AITF(并接受其行为不当客户的警戒),要么冒着失去对投诉接收方的所有访问的风险-这是进行合作的强烈动机,尤其是当接收方是受欢迎的公共访问站点时。我们发现,面对带宽泛滥,AITF保留了接收器带宽的很大一部分,而且这样做的代价是每个客户端的成本已经可以为当今的ISP所负担;只要僵尸网络规模的增长不超过摩尔定律,就不会增加每位客户端的成本。我们还表明,即使部署了AITF的前两个网络在面对带宽泛滥时也可以保持彼此之间的连接性。我们得出的结论是,Internet的网络层可以提供有效,可伸缩且可增量部署的解决方案,以应对带宽泛滥的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号