• DocumentCode
    2923331
  • Title

    Epiphany: A location hiding architecture for protecting critical services from DDoS attacks

  • Author

    Kambhampati, Vamsi ; Papadopolous, Christos ; Massey, Dan

  • fYear
    2012
  • fDate
    25-28 June 2012
  • Firstpage
    1
  • Lastpage
    12
  • Abstract
    Critical services operating over the Internet are increasingly threatened by Distributed Denial of Service (DDoS) attacks. To protect them we propose Epiphany, an architecture that hides the service IP addresses so that attackers cannot locate and target them. Epiphany provides service access through numerous lightweight proxies, presenting a wide target to the attacker. Epiphany has strong location hiding properties; no proxy knows the service address. Instead, proxies communicate over ephemeral paths controlled by the service. If a specific proxy misbehaves or is attacked it can be promptly removed. Epiphany separates proxies into setup and data, and only makes setup proxies public, but these use anycast to create distinct network regions. Clients in clean networks are not affected by attackers in other networks. Data proxies are assigned to clients based on their trust. We evaluate the defense properties of Epiphany using simulations and implementations on PlanetLab and a router testbed.
  • Keywords
    IP networks; Internet; computer network security; telecommunication network routing; DDoS attacks; Epiphany; Internet; PlanetLab; critical service protection; data proxies; distributed denial-of-service attacks; location hiding architecture; router testbed; service IP addresses; Authorization; Computer crime; IP networks; Internet; Routing; Servers; Unicast; Critical Services; DDoS; Hidden Paths; Location Hiding; Proxies;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks (DSN), 2012 42nd Annual IEEE/IFIP International Conference on
  • Conference_Location
    Boston, MA
  • ISSN
    1530-0889
  • Print_ISBN
    978-1-4673-1624-8
  • Electronic_ISBN
    1530-0889
  • Type

    conf

  • DOI
    10.1109/DSN.2012.6263945
  • Filename
    6263945