Blackholing at IXPs: On the Effectiveness of DDoS Mitigation in the Wild

Blackholing at IXPs: On the Effectiveness of DDoS Mitigation in the Wild
复制标题

IXP 黑洞:论野外 DDoS 缓解的有效性

DOI:
10.1007/978-3-319-30505-9_24
复制
发表时间:
2016
期刊:
2008 3rd International Conference on Malicious and Unwanted Software (MALWARE)
影响因子:
--
通讯作者:
Thomas King
Thomas King
中科院分区:
--
文献类型:
--
作者:
C. Dietzel;A. Feldmann;Thomas King

文献摘要

被引文献

相似文献

DDoS攻击不仅对互联网边缘,而且对互联网交换点(IXP)的核心对等链路构成严重威胁。目前,主要的缓解技术是在上游提供商处将流量黑洞到特定的IP前缀。黑洞是一种可操作的技术,它允许对等设备通过BGP向另一个对等设备通告前缀,然后另一个对等设备丢弃发往该前缀的流量。然而,据我们所知,只有坊间证据表明黑洞行动取得了成功。
DDoS attacks remain a serious threat not only to the edge of the Internet but also to the core peering links at Internet Exchange Points (IXPs). Currently, the main mitigation technique is to blackhole traffic to a specific IP prefix at upstream providers. Blackholing is an operational technique that allows a peer to announce a prefix via BGP to another peer, which then discards traffic destined for this prefix. However, as far as we know there is only anecdotal evidence of the success of blackholing.