Title :
SOS: an architecture for mitigating DDoS attacks
Author :
Keromytis, Angelos D. ; Misra, Vishal ; Rubenstein, Dan
Author_Institution :
Comput. Sci. Dept., Columbia Univ., New York, NY, USA
Abstract :
We propose an architecture called secure overlay services (SOS) that proactively prevents denial of service (DoS) attacks, including distributed (DDoS) attacks; it is geared toward supporting emergency services, or similar types of communication. The architecture uses a combination of secure overlay tunneling, routing via consistent hashing, and filtering. We reduce the probability of successful attacks by: 1) performing intensive filtering near protected network edges, pushing the attack point perimeter into the core of the network, where high-speed routers can handle the volume of attack traffic and 2) introducing randomness and anonymity into the forwarding architecture, making it difficult for an attacker to target nodes along the path to a specific SOS-protected destination. Using simple analytical models, we evaluate the likelihood that an attacker can successfully launch a DoS attack against an SOS-protected network. Our analysis demonstrates that such an architecture reduces the likelihood of a successful attack to minuscule levels. Our performance measurements using a prototype implementation indicate an increase in end-to-end latency by a factor of two for the general case, and an average heal time of less than 10 s.
Keywords :
Internet; authorisation; telecommunication network routing; telecommunication security; telecommunication traffic; DoS attacks; Internet; P2P networks; consistent hashing; distributed denial of service attacks; emergency services; end-to-end latency; filtering; forwarding architecture; heal time; peer-to-peer networks; routing; secure communication; secure overlay services; secure overlay tunneling; Analytical models; Computer crime; Emergency services; Filtering; Measurement; Protection; Routing; Telecommunication traffic; Traffic control; Tunneling;
Journal_Title :
Selected Areas in Communications, IEEE Journal on
DOI :
10.1109/JSAC.2003.818807