Title :
MOTAG: Moving Target Defense against Internet Denial of Service Attacks
Author :
Quan Jia ; Kun Sun ; Stavrou, Angelos
Author_Institution :
George Mason Univ., Fairfax, VA, USA
fDate :
July 30 2013-Aug. 2 2013
Abstract :
Distributed Denial of Service (DDoS) attacks still pose a significant threat to critical infrastructure and Internet services alike. In this paper, we propose MOTAG, a moving target defense mechanism that secures service access for authenticated clients against flooding DDoS attacks. MOTAG employs a group of dynamic packet indirection proxies to relay data traffic between legitimate clients and the protected servers. Our design can effectively inhibit external attackers\´ attempts to directly bombard the network infrastructure. As a result, attackers will have to collude with malicious insiders in locating secret proxies and then initiating attacks. However, MOTAG can isolate insider attacks from innocent clients by continuously "moving" secret proxies to new network locations while shuffling client-to-proxy assignments. We develop a greedy shuffling algorithm to minimize the number of proxy re- allocations (shuffles) while maximizing attack isolation. Simulations are used to investigate MOTAG\´s effectiveness on protecting services of different scales against intensified DDoS attacks.
Keywords :
Internet; authorisation; computer network security; telecommunication traffic; DDoS attacks; Internet services; MOTAG; authenticated clients; client-to-proxy assignments; data traffic; distributed denial of service attacks; dynamic packet indirection proxies; greedy shuffling; innocent clients; legitimate clients; malicious insiders; moving target defense against Internet; protected servers; proxy re-allocations; service access; Authentication; Computer crime; Equations; IP networks; Mathematical model; Nickel; Servers;
Conference_Titel :
Computer Communications and Networks (ICCCN), 2013 22nd International Conference on
Conference_Location :
Nassau
Print_ISBN :
978-1-4673-5774-6
DOI :
10.1109/ICCCN.2013.6614155