• DocumentCode
    5138
  • Title

    Vulnerability of Network Mechanisms to Sophisticated DDoS Attacks

  • Author

    Ben-Porat, U. ; Bremler-Barr, Anat ; Levy, Hanoch

  • Author_Institution
    Comput. Eng. & Networks Lab. (TIK), ETH Zurich, Zurich, Switzerland
  • Volume
    62
  • Issue
    5
  • fYear
    2013
  • fDate
    May-13
  • Firstpage
    1031
  • Lastpage
    1043
  • Abstract
    In recent years, we have experienced a wave of DDoS attacks threatening the welfare of the internet. These are launched by malicious users whose only incentive is to degrade the performance of other, innocent, users. The traditional systems turn out to be quite vulnerable to these attacks. The objective of this work is to take a first step to close this fundamental gap, aiming at laying a foundation that can be used in future computer/network designs taking into account the malicious users. Our approach is based on proposing a metric that evaluates the vulnerability of a system. We then use our vulnerability metric to evaluate a data structure which is commonly used in network mechanisms-the Hash table data structure. We show that Closed Hash is much more vulnerable to DDoS attacks than Open Hash, even though the two systems are considered to be equivalent by traditional performance evaluation. We also apply the metric to queuing mechanisms common to computer and communications systems. Furthermore, we apply it to the practical case of a hash table whose requests are controlled by a queue, showing that even after the attack has ended, the regular users still suffer from performance degradation or even a total denial of service.
  • Keywords
    Internet; computer network security; cryptography; DDoS attacks; Distributed Denial of Service attacks; Internet; closed hash; computer-network designs; hash table data structure; malicious users; network mechanism vulnerability; open hash; queuing mechanisms; vulnerability metric; Bandwidth; Complexity theory; Computer crime; Data structures; Degradation; Measurement; Servers; Bandwidth; Complexity theory; Computer crime; DDoS; Data structures; Degradation; Measurement; Servers; hash; malicious; metric; queue; vulnerability;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2012.49
  • Filename
    6158635