• DocumentCode
    3018345
  • Title

    SIFF: a stateless Internet flow filter to mitigate DDoS flooding attacks

  • Author

    Yaar, Abraham ; Perrig, Adrian ; Song, Dawn

  • Author_Institution
    Carneggie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2004
  • fDate
    9-12 May 2004
  • Firstpage
    130
  • Lastpage
    143
  • Abstract
    One of the fundamental limitations of the Internet is the inability of a packet flow recipient to halt disruptive flows before they consume the recipient´s network link resources. Critical infrastructures and businesses alike are vulnerable to DoS attacks or flash-crowds that can incapacitate their networks with traffic floods. Unfortunately, current mechanisms require per-flow state at routers, ISP collaboration, or the deployment of an overlay infrastructure to defend against these events. In this paper, we present SIFF, a Stateless Internet Flow Filter, which allows an end-host to selectively stop individual flows from reaching its network, without any of the common assumptions listed above. We divide all network traffic into two classes, privileged (prioritized packets subject to recipient control) and unprivileged (legacy traffic). Privileged channels are established through a capability exchange handshake. Capabilities are dynamic and verified statelessly by the routers in the network, and can be revoked by quenching update messages to an offending host. SIFF is transparent to legacy clients and servers, but only updated hosts will enjoy the benefits of it.
  • Keywords
    Internet; packet switching; security of data; telecommunication network routing; telecommunication security; telecommunication traffic; DDoS flooding attacks; ISP collaboration; SIFF; Stateless Internet Flow Filter; legacy clients; legacy servers; legacy traffic; network link resources; network routers; network traffic; packet flow; recipient control; router per-flow state; traffic floods; update message quenching; Collaboration; Communication system traffic control; Computer crime; Floods; IP networks; Information filtering; Information filters; Internet; Network servers; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2004. Proceedings. 2004 IEEE Symposium on
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-2136-3
  • Type

    conf

  • DOI
    10.1109/SECPRI.2004.1301320
  • Filename
    1301320