2008 · 13 citations · 16 references
Artificial IntelligenceEngineeringInformation SecurityVerificationComputer-aided VerificationModel VerificationFormal VerificationAttack RatesDenial-of-service AttackAdaptive Selective VerificationDdos DetectionComputer ScienceData SecurityCryptographyAdmission ControlAutomated ReasoningEdge ComputingNetwork Traffic ControlFormal MethodsChannel ModelCongestion ControlFunctional Verification
We consider Denial of Service (DoS) attacks within the province of a shared channel model in which attack rates may be large but are bounded and client request rates vary within fixed bounds. In this setting it is shown that the clients can respond effectively to an attack by using bandwidth as a payment scheme and time-out windows to adaptively boost request rates. The server will be able to process client requests with high probability while pruning out most of the attack by selective random sampling. Our protocol, which we call Adaptive Selective Verification (ASV) is shown to be efficient in terms of bandwidth consumption using both a theoretical model and network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth-based payment by requiring very limited state on the server.
16
Inferring Internet denial-of-service activity
David Moore, Colleen Shannon, Douglas J. Brown et al. · ACM Transactions on Computer Systems · 2006 · 786 citations
Advanced and authenticated marking schemes for IP traceback
Dawn Song, Adrian Perrig · 2002 · 754 citations
Cheng Jin, Haining Wang, Kang G. Shin · 2003 · 472 citations
Hardware Security, Internet Traffic Analysis, Engineering +12
Practical network support for IP traceback
Stefan Savage, David Wetherall, Anna R. Karlin et al. · 2000 · 380 citations
Internet Traffic Analysis, Engineering, Information Security +17