Title :
Overfort: Combating DDoS with peer-to-peer DDoS puzzle
Author :
Khor, Soon Hin ; Nakao, Akihiro
Author_Institution :
Interdiscipl. Inf. Studies, Univ. of Tokyo, Tokyo
Abstract :
The Internet community has been long convinced that distributed denial-of-service (DDoS) attacks are difficult to combat since IP spoofing prevents traceback to the sources of attacks. Even if traceback is possible, the sheer number of sources that must be shutdown renders trace-back, by itself, ineffective. Due to this belief, much effort has been focused on winning the "arms race" against DDoS by over-provisioning resources. This paper shows how Overfort can possibly withstand DDoS onslaughts without being drawn into an arms race by using higher-level traceback to DDoS agents\´ local DNSes (LDNSes) and dealing with those LDNSes instead. Overfort constructs an on-demand overlay using multiple overlay-ingress gateways with their links partitioned into many virtual links - each with different bandwidth and IP - leading to the server to project the illusion of multiple server IPs. An attacker will be faced with the daunting puzzle of finding all the IPs and thereafter the confusion of how much traffic to clog each IP with. Furthermore, Overfort has a mechanism to segregate LDNSes that are serving DDoS agents and restrict them to a limited number of IPs thus saving the other available IPs for productive use. Both proliferation of access channels to the server and LDNS segregation mechanism are the key components in Overfort to defend against DDoS with significantly less resources.
Keywords :
IP networks; Internet; internetworking; peer-to-peer computing; telecommunication security; telecommunication traffic; transport protocols; IP spoofing; Internet community; LDNS segregation mechanism; distributed denial-of-service attack; higher-level traceback; multiple overlay-ingress gateway; network traffic; on-demand overlay construction; peer-to-peer DDoS puzzle; Arm; Bandwidth; Computer crime; Degradation; Face detection; Floods; Internet; Peer to peer computing; Telecommunication traffic; Web server;
Conference_Titel :
Parallel and Distributed Processing, 2008. IPDPS 2008. IEEE International Symposium on
Conference_Location :
Miami, FL
Print_ISBN :
978-1-4244-1693-6
Electronic_ISBN :
1530-2075
DOI :
10.1109/IPDPS.2008.4536561