Routing Around Congestion Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP Routing
نویسنده
چکیده
In this paper, we present Nyx, the first system to both effectively mitigate modern Distributed Denial of Service (DDoS) attacks regardless of the amount of traffic under adversarial control and function without outside cooperation or an Internet redesign. Nyx approaches the problem of DDoS mitigation as a routing problem rather than a filtering problem. This conceptual shift allows Nyx to avoid many of the common shortcomings of existing academic and commercial DDoS mitigation systems. By leveraging how Autonomous Systems (ASes) handle route advertisement in the existing Border Gateway Protocol (BGP), Nyx allows the deploying AS to achieve isolation of traffic from a critical upstream AS off of attacked links and onto alternative, uncongested, paths. This isolation removes the need for filtering or de-prioritizing attack traffic. Nyx controls outbound paths through normal BGP path selection, while return paths from critical ASes are controlled through the use of specific techniques we developed using existing traffic engineering principles and require no outside coordination. Using our own realistic Internet-scale simulator, we find that in more than 98% of cases our system can successfully route critical traffic around network segments under transit-link DDoS attacks; a new form of DDoS attack where the attack traffic never reaches the victim AS, thus invaliding defensive filtering, throttling, or prioritization strategies. More significantly, in over 95% of those cases, the alternate path provides complete congestion relief from transitlink DDoS. Nyx additionally provides complete congestion relief in over 75% of cases when the deployer is being directly attacked.
منابع مشابه
PERFORMANCE EVALUATION OF ROUTE-BASED DISTRIBUTED PACKET FILTERING FOR DDOS PREVENTION IN LARGE-SCALE NETWORKS A Thesis
Kim, HyoJeong. M.S., Purdue University, December, 2003. Performance Evaluation of Route-based Distributed Packet Filtering for DDoS Prevention in Large-scale Networks. Major Professor: Kihong Park. This thesis studies performance evaluation of route-based distributed packet filtering (DPF) for spoofed distributed denial of service (DDoS) attack prevention in large-scale networks under dynamic n...
متن کاملSENSS: Software Defined Security Service
Network attacks have long been an important problem, and have attracted a lot of research in academic and commercial sector. With a rapidly growing number of critical as well as business applications deployed on the Internet today, network attacks have both become more lucrative for the attackers and more damaging to the victims. The implications of network attacks on the victim can be huge. Fo...
متن کاملAn Ant-Based Routing Algorithm for Detecting Attacks in Wireless Sensor Networks
The work proposes a routing algorithm that detects congestion and hence DDoS attack using age, energy and reliability as parameters. Although researchers have proposed number of mechanisms for preventing congestion and attacks in WSN but very few of them have thought of deploying ants as intelligent entities. Moreover, the previous works had been focusing on using parameters like energy, hop an...
متن کاملUnderstanding BGP Session Robustness in Bandwidth Saturation Regime
The reliability and robustness of the Border Gateway Protocol (BGP) play very important roles in achieving highly stable and prompt Internet data communication. The present BGP uses TCP/IP to exchange routing control information. These routing control messages are usually not differentiated from the normal data packets in Internet packet forwarding, and this makes BGP sensitive to severe networ...
متن کاملResilient Interdomain Routing with Bgp – Protocols and Reliability
Interdomain routing is a key element in the global Internet routing infrastructure. A resilient interdomain routing framework is required, in order to deliver reliable and dependable data communication services. However, because the existing routing system has evolved to a large scale and legacy protocols have been widely deployed, building a resilient interdomain routing framework is challengi...
متن کامل