DocumentCode
3434700
Title
FLoc : Dependable Link Access for Legitimate Traffic in Flooding Attacks
Author
Lee, Soo Bum ; Gligor, Virgil D.
Author_Institution
CyLab, Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear
2010
fDate
21-25 June 2010
Firstpage
327
Lastpage
338
Abstract
Malware-contaminated hosts organized as a “bot network” can target and flood network links (e.g., routers). Yet, none of the countermeasures to link flooding proposed to date have provided dependable link access (i.e., bandwidth guarantees) for legitimate traffic during such attacks. In this paper, we present a router subsystem called FLoc (Flow Localization) that confines attack effects and provides differential bandwidth guarantees at a congested link: (1) packet flows of uncontaminated domains (i.e., Autonomous Systems) receive better bandwidth guarantees than packet flows of contaminated ones, and (2) legitimate flows of contaminated domains are guaranteed substantially higher bandwidth than attack flows. FLoc employs new preferential packet-drop and traffic-aggregation policies that limit “collateral damage” and protect legitimate flows from a wide variety of flooding attacks. We present FLoc’s analytical model for dependable link access, a router design based on it, and illustrate FLoc’s effectiveness using simulations of different flooding strategies and comparisons with other flooding defense schemes.
Keywords
Aggregates; Analytical models; Bandwidth; Computer networks; Distributed computing; Floods; IP networks; Protection; Telecommunication traffic; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed Computing Systems (ICDCS), 2010 IEEE 30th International Conference on
Conference_Location
Genoa, Italy
ISSN
1063-6927
Print_ISBN
978-1-4244-7261-1
Type
conf
DOI
10.1109/ICDCS.2010.78
Filename
5541673
Link To Document