PERSIA: a PuzzlE-based InteReSt FloodIng Attack Countermeasure

PERSIA: a PuzzlE-based InteReSt FloodIng Attack Countermeasure
复制标题

DOI:
10.1145/3405656.3418709
复制
发表时间:
2020-09
期刊:
Proceedings of the 7th ACM Conference on Information-Centric Networking
影响因子:
--
通讯作者:
R. Tourani;George Torres;S. Misra
R. Tourani;George Torres;S. Misra
中科院分区:
其他
文献类型:
--
作者:
R. Tourani;George Torres;S. Misra

文献摘要

相似文献

随着智能和连接的移动的、边缘无线设备的激增,分布式拒绝服务(DDoS)攻击正在增加。安全性差、调试不当以及物联网行业的快速、非标准化增长是最近DDoS攻击的主要原因,例如,米拉伊僵尸网络对Dyn的攻击和Memcached对GitHub的攻击。类似于UDP/TCP洪泛(常见的DDoS攻击向量),请求洪泛攻击是命名数据网络(NDN)架构中的主要DDoS漏洞。在本文中,我们提出了PERSIA,一个分布式的请求洪水预防和缓解框架,为启用NDN的ISP,以抵御边缘攻击。PERSIA以边缘为中心的攻击预防机制消除了恶意终端主机成功攻击的可能性。在基础设施(路由器)受损的情况下,PERSIA动态部署网络内缓解策略,以最大限度地减少攻击的规模。我们的实验证明了PERSIA在预防和减轻DDoS攻击方面的弹性和有效性,同时保持合法用户的体验质量(> 99.92%成功的数据包交付率)。
With the proliferation of smart and connected mobile, wireless devices at the edge, Distributed Denial of Service (DDoS) attacks are increasing. Weak security, improper commissioning, and the fast, non-standardized growth of the IoT industry are the major contributors to the recent DDoS attacks, e.g., Mirai Botnet attack on Dyn and Memcached attack on GitHub. Similar to UDP/TCP flooding (common DDoS attack vector), request flooding attack is the primary DDoS vulnerability in the Named-Data Networking (NDN) architecture. In this paper, we propose PERSIA, a distributed request flooding prevention and mitigation framework for NDN-enabled ISPs, to ward-off attacks at the edge. PERSIA's edge-centric attack prevention mechanism eliminates the possibility of successful attacks from malicious end hosts. In the presence of compromised infrastructure (routers), PERSIA dynamically deploys an in-network mitigation strategy to minimize the attack's magnitude. Our experimentation demonstrates PERSIA's resiliency and effectiveness in preventing and mitigating DDoS attacks while maintaining legitimate users' quality of experience (> 99.92% successful packet delivery rate).