Title :
Flow-Cookies: Using Bandwidth Amplification to Defend Against DDoS Flooding Attacks
Author :
Casado, Martin ; Cao, Pei ; Akella, Aditya ; Provos, Niels
Author_Institution :
Stanford Univ.
Abstract :
This paper describes flow-cookies which defend against DDoS flooding attacks using bandwidth amplification. "Flow-cookies" is a mechanism in which a Website can reliably send filtering requests to a cooperating node in the network, leveraging its protection bandwidth. In this approach, a third party provider installs a flow-cookies enabled middlebox called the cookie box, in the network at a high bandwidth link. All traffic to or from the protected Web server must traverse the cookie box. The cookie box guarantees that all packets that pass between it and the server belong to a legitimate TCP flow with a valid sender. This implementation is able to operate at gigabit speeds including per-packet IP filtering of millions of addresses. This approach is also very effective against high volume SYN flooding attacks
Keywords :
IP networks; Internet; Web sites; security of data; telecommunication security; telecommunication traffic; transport protocols; DDoS flooding attack; SYN flooding attack; Web server; Website; bandwidth amplification; cookie box; distributed denial-of-service; flow-cookies; legitimate TCP flow; network traffic; per-packet IP filtering; transport control protocol; Bandwidth; Floods; Information filtering; Information filters; Middleboxes; Network servers; Protection; TCPIP; Telecommunication traffic; Web server;
Conference_Titel :
Quality of Service, 2006. IWQoS 2006. 14th IEEE International Workshop on
Conference_Location :
New Haven, CT
Print_ISBN :
1-4244-0476-2
Electronic_ISBN :
1548-615X
DOI :
10.1109/IWQOS.2006.250484