DocumentCode
3452431
Title
Defending against denial-of-service attacks with puzzle auctions
Author
Wang, XiaoFeng ; Reiter, Michael K.
Author_Institution
Dept. of Electr. & Comput. Eng., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear
2003
fDate
11-14 May 2003
Firstpage
78
Lastpage
92
Abstract
Although client puzzles represent a promising approach to defend against certain classes of denial-of-service attacks, several questions stand in the way of their deployment in practice: e.g., how to set the puzzle difficulty in the presence of an adversary with unknown computing power, and how to integrate the approach with existing mechanisms. In this paper, we attempt to address these questions with a new puzzle mechanism called the puzzle auction. Our mechanism enables each client to "bid" for resources by tuning the difficulty of the puzzles it solves, and to adapt its bidding strategy in response to apparent attacks. We analyze the effectiveness of our auction mechanism and further demonstrate it using an implementation within the TCP protocol stack of the Linux kernel. Our implementation has several appealing properties. It effectively defends against SYN flooding attacks, is fully compatible with TCP, and even provides a degree of interoperability with clients with unmodified kernels: Even without a puzzle-solving kernel, a client still can connect to a puzzle auction server under attack (albeit less effectively than those with puzzle-solving kernels, and at the cost of additional server expense).
Keywords
Internet; client-server systems; computer network management; cryptography; invasive software; network operating systems; operating system kernels; transport protocols; Internet; Linux kernel; SYN flooding attacks; TCP protocol stack; bidding strategy; client bid; client interoperability; denial-of-service attacks; puzzle auction server; puzzle-solving kernel; unmodified kernels; Computer crime; Privacy; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy, 2003. Proceedings. 2003 Symposium on
ISSN
1081-6011
Print_ISBN
0-7695-1940-7
Type
conf
DOI
10.1109/SECPRI.2003.1199329
Filename
1199329
Link To Document