• DocumentCode
    1566058
  • Title

    Anti-DDoS Virtualized Operating System

  • Author

    Garg, Sanjam ; Saran, Huzur

  • Author_Institution
    Indian Inst. of Technol., Delhi
  • fYear
    2008
  • Firstpage
    667
  • Lastpage
    674
  • Abstract
    It is easier to detect a DDoS attack near the victim but it is of little use to do so. Many researchers believe that it would be best to handle DDoS attacks closer to the computers which host these attacks and have propounded various strategies for packet filtering at edge-routers. This paper makes three contributions over earlier work. First, we propose that it is best to track illegitimate packets suspected to cause a DDoS at the source computer itself. Secondly, we come up with a secure and efficient implementation (ADVOS: Anti-DDoS Virtualized Operating System) for packet filtering at the source computer itself. Security dependency on the integrity of the source operating system is removed by using virtualization to isolate the modules providing the protection capabilities. Different models of traffic characterization could possibly be used in curtailing malicious traffic, we justify the effectiveness of symmetry based model at source computers. Thirdly, we demonstrate that such an anti-DDoS operating system using virtualization can be implemented practically and efficiently. In our prototype over native Linux system 2.4% overhead was observed in the attained network throughput. Less than 1% of the total attack traffic generated was allowed to pass through on attack. Finally, we discuss the scalability and deployment issues for ADVOS.
  • Keywords
    Linux; security of data; virtual machines; Linux system; antiDDoS virtualized operating system; malicious traffic; packet filtering; security dependency; Computer crime; Filtering; Linux; Operating systems; Protection; Prototypes; Scalability; Telecommunication traffic; Throughput; Traffic control; Distributed Denial of Service Attack; Malware; Performance; Virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3102-1
  • Type

    conf

  • DOI
    10.1109/ARES.2008.120
  • Filename
    4529407