Title :
EC: an edge-based architecture against DDoS attacks and malware spread
Author :
Karrer, Roger P.
Author_Institution :
Deutsche Telekom Labs., Technische Univ. Berlin
Abstract :
The ability to limit unsolicited traffic in the Internet is important to defy DDoS attacks and to contain the spread of worms and viruses. The concept of capabilities, which requires that sources must acquire tokens prior to sending data, has been successfully applied on an end-to-end base to protect end systems. In this paper, we propose edge-based capabilities (EC), an architecture that prevents DDoS attacks and malware spread at the edge. EC introduces a novel network element termed gate. The gate controls IP packets that have previously been authenticated by an end-to-end mechanism. Authenticated traffic carries a session-specific tag in the IP header. Packets with valid tags are forwarded by the gate whereas traffic without or with wrong tags is treated with low priority or even dropped. EC achieves efficiency and scalability by defining a single lock against which tags are compared, removing the need to store per-flow information in the gate. Compared to related proposals, EC is easy to deploy as the gate can be added incrementally and EC requires only a single network element to be added at the edge
Keywords :
IP networks; Internet; computer viruses; quality of service; security of data; telecommunication security; telecommunication traffic; DDoS attack; IP packet; Internet; Internet protocol; authenticated traffic; distributed denial-of-service; edge-based capability; gate; malware spread; scalability; session-specific tag; virus; Authentication; Communication system traffic control; Computer crime; Computer worms; Floods; Internet; Network servers; Protection; Telecommunication traffic; Web server;
Conference_Titel :
Advanced Information Networking and Applications, 2006. AINA 2006. 20th International Conference on
Conference_Location :
Vienna
Print_ISBN :
0-7695-2466-4
DOI :
10.1109/AINA.2006.159