DocumentCode
2923331
Title
Epiphany: A location hiding architecture for protecting critical services from DDoS attacks
Author
Kambhampati, Vamsi ; Papadopolous, Christos ; Massey, Dan
fYear
2012
fDate
25-28 June 2012
Firstpage
1
Lastpage
12
Abstract
Critical services operating over the Internet are increasingly threatened by Distributed Denial of Service (DDoS) attacks. To protect them we propose Epiphany, an architecture that hides the service IP addresses so that attackers cannot locate and target them. Epiphany provides service access through numerous lightweight proxies, presenting a wide target to the attacker. Epiphany has strong location hiding properties; no proxy knows the service address. Instead, proxies communicate over ephemeral paths controlled by the service. If a specific proxy misbehaves or is attacked it can be promptly removed. Epiphany separates proxies into setup and data, and only makes setup proxies public, but these use anycast to create distinct network regions. Clients in clean networks are not affected by attackers in other networks. Data proxies are assigned to clients based on their trust. We evaluate the defense properties of Epiphany using simulations and implementations on PlanetLab and a router testbed.
Keywords
IP networks; Internet; computer network security; telecommunication network routing; DDoS attacks; Epiphany; Internet; PlanetLab; critical service protection; data proxies; distributed denial-of-service attacks; location hiding architecture; router testbed; service IP addresses; Authorization; Computer crime; IP networks; Internet; Routing; Servers; Unicast; Critical Services; DDoS; Hidden Paths; Location Hiding; Proxies;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks (DSN), 2012 42nd Annual IEEE/IFIP International Conference on
Conference_Location
Boston, MA
ISSN
1530-0889
Print_ISBN
978-1-4673-1624-8
Electronic_ISBN
1530-0889
Type
conf
DOI
10.1109/DSN.2012.6263945
Filename
6263945
Link To Document