DocumentCode
2286650
Title
High performance distributed Denial-of-Service resilient web cluster architecture
Author
Ranjan, Supranamaya ; Knightly, Edward
Author_Institution
Narus Inc., Mountain View, CA
fYear
2008
fDate
7-11 April 2008
Firstpage
1019
Lastpage
1024
Abstract
Though the WWW has come a long way since when it was monikered the World Wide Wait, it is still not reliable during heavy workload conditions. Overloads due to sudden arrival of users (flash crowds) is known to exponentially increase download times. More recently, online banks and portals have been the target of Distributed Denial-of-Service (DDoS) attacks, which send a deluge of requests and drive away the legitimate users. These overloads pose a new set of challenges towards efficient operation at enterprises that host web content which this dissertation addresses by combining knowledge of the network as well as server performance. In particular, this dissertation proposes a web hosting architecture consisting of a grid of clusters, to provide high-performance in the presence of standard overload conditions as well as resilience during attacks. The architecture\´s high-performance component is provided by a server selection framework which selects the "best server" to serve a request as well as allows for an efficient multiplexing of resources across the entire cluster grid. Traditional approaches assume that minimizing network hop count minimizes client latency. In contrast, the proposed mechanism for server selection collects fine-grained server load and network latency measurements and forwards requests to the server that minimizes the total of estimated network and server delays. The architecture\´s DDoS- resilience is provided via a combination of anomaly detection and scheduling based mitigation of DDoS attacks. In contrast to prior work, the suspicion mechanism assigns a continuous valued vs. binary suspicion measure to each client session, and the scheduler utilizes these values to determine if and when to schedule a session\´s requests. Via a combination of analytical modeling and testbed experiments over an online bookstore implementation, the performance benefits achieved by the proposed cluster architecture are justified.
Keywords
Internet; Web sites; delays; network servers; DDoS attacks; World Wide Wait; client latency; cluster grid; distributed denial-of-service attacks; fine-grained server load; network hop count; network server; resilient Web cluster; server delays; Analytical models; Computer crime; Delay estimation; Drives; Network servers; Performance analysis; Portals; Resilience; Service oriented architecture; World Wide Web;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium, 2008. NOMS 2008. IEEE
Conference_Location
Salvador, Bahia
ISSN
1542-1201
Print_ISBN
978-1-4244-2065-0
Electronic_ISBN
1542-1201
Type
conf
DOI
10.1109/NOMS.2008.4575272
Filename
4575272
Link To Document