STONE: a stream-based DDoS defense framework

STONE: a stream-based DDoS defense framework
复制标题

STONE:基于流的 DDoS 防御框架

DOI:
--
复制
发表时间:
2013
期刊:
ACM Symposium on Applied Computing
影响因子:
--
通讯作者:
M. Patiño
M. Patiño
中科院分区:
--
文献类型:
--
作者:
Mar Callau;R. Jiménez;Vincenzo Gulisano;M. Papatriantafilou;Zhang Fu;M. Patiño

文献摘要

被引文献

相似文献

一个有效的分布式拒绝服务(DDoS)防御机制必须保证合法用户访问Internet服务,掩盖可能的攻击的影响。也就是说,它必须能够检测威胁并以在线方式丢弃恶意数据包。鉴于新兴的数据流技术可以有效地实现这种缓解,在本文中,我们提出了石头,基于流的DDoS防御框架,它集成了基于异常的DDoS检测和缓解与可扩展的数据流技术。 使用STONE,通过持续的数据流查询来分析潜在目标的流量,维护用于攻击检测和缓解的信息。STONE在DDoS攻击期间对合法用户流量的影响最小,并且它还有效地面对Flash人群。我们的初步评估的基础上实现的原型和进行真实的合法和恶意的流量跟踪表明,石头是能够提供快速检测和精确缓解DDoS攻击利用可扩展的数据流技术。
An effective Distributed Denial of Service (DDoS) defense mechanism must guarantee legitimate users access to an Internet service masking the effects of possible attacks. That is, it must be able to detect threats and discard malicious packets in a online fashion. Given that emerging data streaming technology can enable such mitigation in an effective manner, in this paper we present STONE, a stream-based DDoS defense framework, which integrates anomaly-based DDoS detection and mitigation with scalable data streaming technology. With STONE, the traffic of potential targets is analyzed via continuous data streaming queries maintaining information used for both attack detection and mitigation. STONE provides minimal degradation of legitimate users traffic during DDoS attacks and it also faces effectively flash crowds. Our preliminary evaluation based on an implemented prototype and conducted with real legitimate and malicious traffic traces shows that STONE is able to provide fast detection and precise mitigation of DDoS attacks leveraging scalable data streaming technology.