• DocumentCode
    3434700
  • Title

    FLoc : Dependable Link Access for Legitimate Traffic in Flooding Attacks

  • Author

    Lee, Soo Bum ; Gligor, Virgil D.

  • Author_Institution
    CyLab, Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2010
  • fDate
    21-25 June 2010
  • Firstpage
    327
  • Lastpage
    338
  • Abstract
    Malware-contaminated hosts organized as a “bot network” can target and flood network links (e.g., routers). Yet, none of the countermeasures to link flooding proposed to date have provided dependable link access (i.e., bandwidth guarantees) for legitimate traffic during such attacks. In this paper, we present a router subsystem called FLoc (Flow Localization) that confines attack effects and provides differential bandwidth guarantees at a congested link: (1) packet flows of uncontaminated domains (i.e., Autonomous Systems) receive better bandwidth guarantees than packet flows of contaminated ones, and (2) legitimate flows of contaminated domains are guaranteed substantially higher bandwidth than attack flows. FLoc employs new preferential packet-drop and traffic-aggregation policies that limit “collateral damage” and protect legitimate flows from a wide variety of flooding attacks. We present FLoc’s analytical model for dependable link access, a router design based on it, and illustrate FLoc’s effectiveness using simulations of different flooding strategies and comparisons with other flooding defense schemes.
  • Keywords
    Aggregates; Analytical models; Bandwidth; Computer networks; Distributed computing; Floods; IP networks; Protection; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems (ICDCS), 2010 IEEE 30th International Conference on
  • Conference_Location
    Genoa, Italy
  • ISSN
    1063-6927
  • Print_ISBN
    978-1-4244-7261-1
  • Type

    conf

  • DOI
    10.1109/ICDCS.2010.78
  • Filename
    5541673