Stellar: network attack mitigation using advanced blackholing

Stellar: network attack mitigation using advanced blackholing
复制标题

Stellar:使用高级黑洞缓解网络攻击

DOI:
--
复制
发表时间:
2018
期刊:
Conference on Emerging Network Experiment and Technology
影响因子:
--
通讯作者:
A. Feldmann
A. Feldmann
中科院分区:
--
文献类型:
--
作者:
C. Dietzel;Georgios Smaragdakis;M. Wichtlhuber;A. Feldmann

文献摘要

参考文献

被引文献

相似文献

包括分布式拒绝服务(DDoS)在内的网络攻击在带宽沿着损失不断增加(最近的攻击超过1.7 Tbps),并对目标公司/政府造成破坏性影响。多年来,缓解技术,从黑洞到路由器上基于策略的过滤,再到流量清洗,都已被添加到网络运营商的工具箱中。即使这些缓解技术提供了一些保护,它们也会产生严重的附带损害,例如,丢弃合法流量(黑洞),成本密集型,或无法很好地扩展到Tbps级别的攻击(ACL过滤,流量清理),或需要合作和资源共享(Flowspec)。在本文中,我们提出了先进的黑洞和它的系统实现恒星。高级黑洞建立在黑洞的可扩展性之上,同时通过增加其粒度来限制附带损害。此外,Stellar降低了为提高缓解效果所需的合作水平。我们表明,细粒度黑洞可以实现,例如,在一个主要的IXP,通过结合可用的硬件过滤器与新的信令机制。我们在一个大型IXP上评估了Stellar的可扩展性和性能,该IXP互连了800多个网络,交换了超过6 Tbps的流量,每天都有许多网络攻击。我们的研究结果表明,网络攻击,例如,DDoS放大攻击可以成功缓解,同时受到攻击的网络和服务继续运行不受干扰。
Network attacks, including Distributed Denial-of-Service (DDoS), continuously increase in terms of bandwidth along with damage (recent attacks exceed 1.7 Tbps) and have a devastating impact on the targeted companies/governments. Over the years, mitigation techniques, ranging from blackholing to policy-based filtering at routers, and on to traffic scrubbing, have been added to the network operator's toolbox. Even though these mitigation techniques provide some protection, they either yield severe collateral damage, e.g., dropping legitimate traffic (blackholing), are cost-intensive, or do not scale well for Tbps level attacks (ACL filtering, traffic scrubbing), or require cooperation and sharing of resources (Flowspec). In this paper, we propose Advanced Blackholing and its system realization Stellar. Advanced blackholing builds upon the scalability of blackholing while limiting collateral damage by increasing its granularity. Moreover, Stellar reduces the required level of cooperation to enhance mitigation effectiveness. We show that fine-grained blackholing can be realized, e.g., at a major IXP, by combining available hardware filters with novel signaling mechanisms. We evaluate the scalability and performance of Stellar at a large IXP that interconnects more than 800 networks, exchanges more than 6 Tbps traffic, and witnesses many network attacks every day. Our results show that network attacks, e.g., DDoS amplification attacks, can be successfully mitigated while the networks and services under attack continue to operate untroubled.
关于 BGP Flowspec 在两个来源(ISP 和 IXP)缓解 DDoS 方面的潜力
DOI: 10.1145/3234200.3234209
发表时间: 2018
期刊: SIGCOMM '18 Proceedings of the ACM SIGCOMM 2018 Conference on Posters and Demos
影响因子: --
作者:
Hinze, Nico;Nawrocki, Marcin;Jonker, Mattijs;Dainotti, Alberto;Schmidt, Thomas C.;Wählisch, Matthias
通讯作者: Wählisch, Matthias