Publication | Closed Access
CoDef
98
Citations
29
References
2013
Year
Unknown Venue
Collaborative DefenseInternet SecurityInternet Traffic AnalysisEngineeringDdos DetectionEdge ComputingInformation SecurityDenial-of-service AttackNetwork AnalysisLegitimate TrafficComputer ScienceBotnet DetectionInternet LinksData SecurityCryptography
Large-scale botnet attacks against Internet links using low-rate flows cannot be effectively countered by any of the traditional rate-limiting and flow-filtering mechanisms deployed in individual routers. In this paper, we present a collaborative defense mechanism, called CoDef, which enables routers to distinguish low-rate attack flows from legitimate flows, and protect legitimate traffic during botnet attacks. CoDef enables autonomous domains that are uncontaminated by bots to collaborate during link flooding attacks and reroute their customers' legitimate traffic in response to requests from congested routers. Collaborative defense using multi-path routing favors legitimate traffic while limiting the bandwidth available to attack traffic at a congested link. We present CoDef's design and evaluate its effectiveness by exploring the domain-level path-diversity of the Internet and performing simulations under various traffic conditions.
| Year | Citations | |
|---|---|---|
Page 1
Page 1