• DocumentCode
    1972881
  • Title

    Backward traffic throttling to mitigate bandwidth floods

  • Author

    Gev, Yehoshua ; Geva, Moti ; Herzberg, Amir

  • Author_Institution
    Comput. Sci. Dept., Bar Ilan Univ., Ramat-Gan, Israel
  • fYear
    2012
  • fDate
    3-7 Dec. 2012
  • Firstpage
    904
  • Lastpage
    910
  • Abstract
    We present Backward Traffic Throttling (BTT), an efficient, decentralized mechanism for congestion and bandwidth-flooding attacks mitigation. Upon congestion, BTT employs three basic mechanisms to throttle excessive traffic, namely: prioritize legitimate flows, shape traffic, and request upstream BTT nodes to similarly prioritize and shape traffic. Flow prioritizing parameters are determined independently by each BTT server, based on typical traffic estimations. BTT is easily deployed: it requires no changes to routers, and does not modify traffic. Instead, BTT configures routers´ queuing discipline and traffic shapers. Both simulation and testbed experiments were performed to asses the effectiveness of BTT during distributed denial-of-service (DDoS) attacks. Results show that even limited BTT deployment alleviates attacks damage and allows legitimate TCP traffic to sustain communication, whereas larger deployments maintain larger portions of the original bandwidth.
  • Keywords
    computer network security; telecommunication traffic; transport protocols; BTT; DDoS attacks; TCP traffic; backward traffic throttling; bandwidth floods; bandwidth-flooding attacks mitigation; decentralized mechanism; distributed denial-of-service attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2012 IEEE
  • Conference_Location
    Anaheim, CA
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4673-0920-2
  • Electronic_ISBN
    1930-529X
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2012.6503228
  • Filename
    6503228