• DocumentCode
    2286650
  • Title

    High performance distributed Denial-of-Service resilient web cluster architecture

  • Author

    Ranjan, Supranamaya ; Knightly, Edward

  • Author_Institution
    Narus Inc., Mountain View, CA
  • fYear
    2008
  • fDate
    7-11 April 2008
  • Firstpage
    1019
  • Lastpage
    1024
  • Abstract
    Though the WWW has come a long way since when it was monikered the World Wide Wait, it is still not reliable during heavy workload conditions. Overloads due to sudden arrival of users (flash crowds) is known to exponentially increase download times. More recently, online banks and portals have been the target of Distributed Denial-of-Service (DDoS) attacks, which send a deluge of requests and drive away the legitimate users. These overloads pose a new set of challenges towards efficient operation at enterprises that host web content which this dissertation addresses by combining knowledge of the network as well as server performance. In particular, this dissertation proposes a web hosting architecture consisting of a grid of clusters, to provide high-performance in the presence of standard overload conditions as well as resilience during attacks. The architecture\´s high-performance component is provided by a server selection framework which selects the "best server" to serve a request as well as allows for an efficient multiplexing of resources across the entire cluster grid. Traditional approaches assume that minimizing network hop count minimizes client latency. In contrast, the proposed mechanism for server selection collects fine-grained server load and network latency measurements and forwards requests to the server that minimizes the total of estimated network and server delays. The architecture\´s DDoS- resilience is provided via a combination of anomaly detection and scheduling based mitigation of DDoS attacks. In contrast to prior work, the suspicion mechanism assigns a continuous valued vs. binary suspicion measure to each client session, and the scheduler utilizes these values to determine if and when to schedule a session\´s requests. Via a combination of analytical modeling and testbed experiments over an online bookstore implementation, the performance benefits achieved by the proposed cluster architecture are justified.
  • Keywords
    Internet; Web sites; delays; network servers; DDoS attacks; World Wide Wait; client latency; cluster grid; distributed denial-of-service attacks; fine-grained server load; network hop count; network server; resilient Web cluster; server delays; Analytical models; Computer crime; Delay estimation; Drives; Network servers; Performance analysis; Portals; Resilience; Service oriented architecture; World Wide Web;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium, 2008. NOMS 2008. IEEE
  • Conference_Location
    Salvador, Bahia
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4244-2065-0
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2008.4575272
  • Filename
    4575272