返回
SOS: An architecture for mitigating DDoS attacks
DOI:10.1109/JSAC.2003.818807.png)
摘要
En 中文
We propose an architecture called secure overlay services (SOS) that proactively. prevents denial of service (DoS) attacks, geared toward supporting emergency services, or similar types of communication. The architecture uses a combination of secure overlay tunneling, routing via consistent hashing, and filtering. We reduce the probability of successful attacks by: 1) performing intensive filtering near protected network edges, pushing the attack point perimeter into the core of the network, where high-speed routers can handle the volume of attack traffic and 2) introducing randomness and anonymity into the forwarding architecture, making it difficult for an attacker to target nodes along the path to a specific SOS-protected destination. Using simple analytical models, we evaluate the likelihood that an attacker can successfully launch a DoS attack against an SOS-protected network. Our analysis demonstrates that such an architecture reduces the likelihood of a successful attack to minuscule levels. Our performance measurements using a prototype implementation indicate an increase in end-to-end latency by a factor of two for the general case, and an average heal time of less than 10 s.
Keyword:
access control
denial of service (DoS) attacks
overlay networks
packet filtering
peer-to-peer (P2P) networks
期刊
IF:
17.2
论文数:
6.4K
被引数:
3.1W
机构
暂无机构信息
引用论文
Synthesis and characterization of magnetic nanoparticles coated with silica through a sol-gel approach
Cerâmica
IF0
Polymerization and depolymerization of microtubules in vitro as studied by flow birefringence
FEBS Letters
IF0
CANDIDA INFECTION OF LOCAL NECROSIS IN SEVERE ACUTE PANCREATITIS IS ASSOCIATED WITH INCREASED MORTALITY
Shock
IF0

