首页> 外文期刊>IEEE Journal on Selected Areas in Communications >SOS: an architecture for mitigating DDoS attacks
【24h】

SOS: an architecture for mitigating DDoS attacks

机译:SOS:用于缓解DDoS攻击的体系结构

获取原文
获取原文并翻译 | 示例
       

摘要

We propose an architecture called secure overlay services (SOS) that proactively prevents denial of service (DoS) attacks, including distributed (DDoS) attacks; it is geared toward supporting emergency services, or similar types of communication. The architecture uses a combination of secure overlay tunneling, routing via consistent hashing, and filtering. We reduce the probability of successful attacks by: 1) performing intensive filtering near protected network edges, pushing the attack point perimeter into the core of the network, where high-speed routers can handle the volume of attack traffic and 2) introducing randomness and anonymity into the forwarding architecture, making it difficult for an attacker to target nodes along the path to a specific SOS-protected destination. Using simple analytical models, we evaluate the likelihood that an attacker can successfully launch a DoS attack against an SOS-protected network. Our analysis demonstrates that such an architecture reduces the likelihood of a successful attack to minuscule levels. Our performance measurements using a prototype implementation indicate an increase in end-to-end latency by a factor of two for the general case, and an average heal time of less than 10 s.
机译:我们提出了一种称为安全覆盖服务(SOS)的体系结构,该体系可主动防止拒绝服务(DoS)攻击,包括分布式(DDoS)攻击;它旨在支持紧急服务或类似类型的通信。该体系结构结合了安全覆盖隧道,通过一致的哈希进行路由和过滤的组合。我们通过以下方法降低成功攻击的可能性:1)在受保护的网络边缘附近执行密集过滤,将攻击点边界推入网络的核心,高速路由器可以处理攻击流量,以及2)引入随机性和匿名性到转发体系结构中,使攻击者很难将目标定向到通往受SOS保护的特定目标的路径。使用简单的分析模型,我们评估攻击者可以针对受SOS保护的网络成功发起DoS攻击的可能性。我们的分析表明,这种体系结构可将成功攻击的可能性降低到很小的水平。我们使用原型实现的性能测量结果表明,在一般情况下,端到端延迟增加了两倍,平均修复时间少于10 s。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号