Community Cleanup: Incentivizing Network Hygiene via Distributed Attack Reporting

Community Cleanup: Incentivizing Network Hygiene via Distributed Attack Reporting
复制标题

DOI:
10.1109/noms47738.2020.9110446
复制
发表时间:
2020-04
期刊:
NOMS 2020 - 2020 IEEE/IFIP Network Operations and Management Symposium
影响因子:
--
通讯作者:
Yu Liu;Craig A. Shue
Yu Liu;Craig A. Shue
中科院分区:
其他
文献类型:
--
作者:
Yu Liu;Craig A. Shue

文献摘要

相似文献

由于资源限制和缺乏当地安全专业知识,住宅网络很难确保安全。这些网络主要使用缺乏有意义的安全机制的消费级路由器,为对手发起攻击提供了一个安全的避风港,包括破坏性的分布式拒绝服务(DDoS)攻击。之前的努力建议将住宅网络安全外包给专家,但激励用户采用一直是一个挑战。这项工作探讨了将住宅SDN技术与先前的协同DDoS报告工作相结合,以识别住宅网络的危害。这种组合为最终用户部署该技术提供了激励,包括在他们自己的设备上快速通知危害,减少上游带宽消耗,同时产生最小的性能开销。
Residential networks are difficult to secure due to resource constraints and lack of local security expertise. These networks primarily use consumer-grade routers that lack meaningful security mechanisms, providing a safe-haven for adversaries to launch attacks, including damaging distributed denial-of-service (DDoS) attacks. Prior efforts have suggested outsourcing residential network security to experts, but motivating user adoption has been a challenge. This work explores combining residential SDN techniques with prior work on collaborative DDoS reporting to identify residential network compromises. This combination provides incentives for end-users to deploy the technique, including rapid notification of compromises on their own devices and reduced upstream bandwidth consumption, while incurring minimal performance overheads.