• DocumentCode
    2784398
  • Title

    In-network server-directed client authentication and packet classification

  • Author

    Jamshed, Muhammad ; Brustoloni, Jose

  • Author_Institution
    Electr. Eng. Dept., KAIST, Daejeon, South Korea
  • fYear
    2010
  • fDate
    10-14 Oct. 2010
  • Firstpage
    328
  • Lastpage
    331
  • Abstract
    Defenses against Distributed Denial-of-Service (DDoS) attacks are commercially available and deployed by Internet Service Providers (ISPs) at the network and transport layers. However, attackers increasingly target vulnerabilities at the application layer. Launched from bots, these attacks seek to exhaust server resources, such as CPU and disk bandwidth. Because these attacks use normal-looking requests, ISP defenses can´t distinguish them. We describe Forward Sentinel (FS), a novel device that enables ISPs to protect servers against such attacks. When load on a server reaches a level suggestive of attack, FS intercepts traffic and requires the server´s clients to authenticate. Moreover, protected servers can signal to FS the desired class of service for a client´s packets (e.g., after client authentication by the server). FS can be configured to mark packets for different classes of service or drop them according to the results of client authentication, number of packets forwarded, and server signaling. Experiments demonstrate that FS can effectively protect servers against DDoS attacks at the network, transport, and application layers.
  • Keywords
    Internet; network servers; telecommunication security; DDoS; ISP; Internet service providers; client authentication; disk bandwidth; distributed denial-of-service attacks; forward sentinel; in-network server-directed client authentication; normal-looking requests; packet classification; server resources; server signaling; Authentication; Computer crime; IP networks; Quality of service; Time factors; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks (LCN), 2010 IEEE 35th Conference on
  • Conference_Location
    Denver, CO
  • ISSN
    0742-1303
  • Print_ISBN
    978-1-4244-8387-7
  • Type

    conf

  • DOI
    10.1109/LCN.2010.5735734
  • Filename
    5735734