• DocumentCode
    1691133
  • Title

    Overfort: Combating DDoS with peer-to-peer DDoS puzzle

  • Author

    Khor, Soon Hin ; Nakao, Akihiro

  • Author_Institution
    Interdiscipl. Inf. Studies, Univ. of Tokyo, Tokyo
  • fYear
    2008
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The Internet community has been long convinced that distributed denial-of-service (DDoS) attacks are difficult to combat since IP spoofing prevents traceback to the sources of attacks. Even if traceback is possible, the sheer number of sources that must be shutdown renders trace-back, by itself, ineffective. Due to this belief, much effort has been focused on winning the "arms race" against DDoS by over-provisioning resources. This paper shows how Overfort can possibly withstand DDoS onslaughts without being drawn into an arms race by using higher-level traceback to DDoS agents\´ local DNSes (LDNSes) and dealing with those LDNSes instead. Overfort constructs an on-demand overlay using multiple overlay-ingress gateways with their links partitioned into many virtual links - each with different bandwidth and IP - leading to the server to project the illusion of multiple server IPs. An attacker will be faced with the daunting puzzle of finding all the IPs and thereafter the confusion of how much traffic to clog each IP with. Furthermore, Overfort has a mechanism to segregate LDNSes that are serving DDoS agents and restrict them to a limited number of IPs thus saving the other available IPs for productive use. Both proliferation of access channels to the server and LDNS segregation mechanism are the key components in Overfort to defend against DDoS with significantly less resources.
  • Keywords
    IP networks; Internet; internetworking; peer-to-peer computing; telecommunication security; telecommunication traffic; transport protocols; IP spoofing; Internet community; LDNS segregation mechanism; distributed denial-of-service attack; higher-level traceback; multiple overlay-ingress gateway; network traffic; on-demand overlay construction; peer-to-peer DDoS puzzle; Arm; Bandwidth; Computer crime; Degradation; Face detection; Floods; Internet; Peer to peer computing; Telecommunication traffic; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Processing, 2008. IPDPS 2008. IEEE International Symposium on
  • Conference_Location
    Miami, FL
  • ISSN
    1530-2075
  • Print_ISBN
    978-1-4244-1693-6
  • Electronic_ISBN
    1530-2075
  • Type

    conf

  • DOI
    10.1109/IPDPS.2008.4536561
  • Filename
    4536561