首页> 外文OA文献 >SIFF: A Stateless Internet Flow Filter to Mitigate DDoS Flooding Attacks
【2h】

SIFF: A Stateless Internet Flow Filter to Mitigate DDoS Flooding Attacks

机译:SIFF:缓解DDoS泛洪攻击的无状态Internet流过滤器

摘要

One of the fundamental limitations of the Internet is the inability of a packet flow recipient to halt disruptive flows before they consume the recipient’s network link resources. Critical infrastructures and businesses alike are vulnerable to DoS attacks or flash-crowds that can incapacitate their networks with traffic floods. Unfortunately, current mechanisms require per-flow state at routers, ISP collaboration, or the deployment of an overlay infrastructure to defend against these events.In this paper, we present SIFF, a Stateless Internet Flow Filter, which allows an end-host to selectively stop individual flows from reaching its network, without any of the common assumptions listed above. We divide all network traffic into two classes, privileged (prioritized packets subject to recipient control) and unprivileged (legacy traffic). Privileged channels are established through a capability exchange handshake. Capabilities are dynamic and verified statelessly by the routers in the network, and can be revoked by quenching update messages to an offending host. SIFF is transparent to legacy clients and servers, but only updated hosts will enjoy the benefits of it.
机译:互联网的基本限制之一是,数据包流接收者无法在破坏性流消耗接收者的网络链接资源之前将其中断。关键基础设施和企业都容易受到DoS攻击或闪存人群的攻击,这些攻击或闪存人群可能会因流量泛滥而使网络瘫痪。不幸的是,当前的机制需要路由器的每流状态,ISP协作或部署覆盖基础结构来防御这些事件。在本文中,我们介绍了SIFF,一种无状态Internet流过滤器,它允许最终主机选择性地进行在没有上面列出的任何常见假设的情况下,阻止单个流量到达其网络。我们将所有网络流量分为两类,特权(受接收者控制的优先数据包)和非特权(传统流量)。通过能力交换握手建立特权通道。功能是动态的,并且可以通过网络中的路由器进行无状态验证,并且可以通过取消更新到有问题主机的更新消息来撤销这些功能。 SIFF对旧版客户端和服务器透明,但是只有更新的主机才能享受它的好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号