SurgeProtector: mitigating temporal algorithmic complexity attacks using adversarial scheduling

SurgeProtector: mitigating temporal algorithmic complexity attacks using adversarial scheduling
复制标题

DOI:
10.1145/3544216.3544250
复制
发表时间:
2022-08
期刊:
Proceedings of the ACM SIGCOMM 2022 Conference
影响因子:
--
通讯作者:
Nirav Atre;Hugo Sadok;Erica Chiang;Weina Wang;Justine Sherry
Nirav Atre;Hugo Sadok;Erica Chiang;Weina Wang;Justine Sherry
中科院分区:
其他
文献类型:
--
作者:
Nirav Atre;Hugo Sadok;Erica Chiang;Weina Wang;Justine Sherry

文献摘要

相似文献

拒绝服务(DoS)攻击是面向公众的网络部署的祸根。网络复杂性攻击(ACA)是一类DoS攻击,攻击者使用少量的对抗性流量在目标系统中引发大量工作,使系统过载并导致其丢弃无辜用户的数据包。ACA是特别危险的,因为与批量拒绝服务攻击不同,ACA不需要攻击者大量的网络带宽投资。今天,互联网上的网络功能(NF)必须根据具体情况进行设计和工程,以减轻ACA的破坏性影响。此外,由此产生的设计往往是过于保守的攻击缓解策略,限制了无辜的流量,NF可以在普通情况下的操作。在这项工作中,我们提出了一个更一般的框架,使NF弹性ACA。我们的框架,SurgeProtector,使用NF的调度程序,以减轻使用非常传统的调度算法的ACA的影响:加权最短作业优先(WSJF)。为了评估SurgeProtector,我们提出了一种新的脆弱性度量标准,称为位移因子(DF),它量化了对手可以对系统造成的“每单位努力的伤害”。我们提供了新的,对抗性的分析WSJF,并表明,任何系统使用这种政策有一个最坏的情况下DF只有一个小的常数,传统的加密货币没有上限的DF。说明SurgeProtector不仅在理论上,但实际上是强大的,我们将SurgeProtector集成到一个开源的入侵检测系统(IDS)。在模拟攻击下,SurgeProtector增强的IDS遭受的无辜流量损失比原系统低90- 99%。
Denial-of-Service (DoS) attacks are the bane of public-facing network deployments. Algorithmic complexity attacks (ACAs) are a class of DoS attacks where an attacker uses a small amount of adversarial traffic to induce a large amount of work in the target system, pushing the system into overload and causing it to drop packets from innocent users. ACAs are particularly dangerous because, unlike volumetric DoS attacks, ACAs don't require a significant network bandwidth investment from the attacker Today, network functions (NFs) on the Internet must be designed and engineered on a case-by-case basis to mitigate the debilitating impact of ACAs. Further, the resulting designs tend to be overly conservative in their attack mitigation strategy, limiting the innocent traffic that the NF can serve under common-case operation. In this work, we propose a more general framework to make NFs resilient to ACAs. Our framework, SurgeProtector, uses the NF's scheduler to mitigate the impact of ACAs using a very traditional scheduling algorithm: Weighted Shortest Job First (WSJF). To evaluate SurgeProtector, we propose a new metric of vulnerability called the Displacement Factor (DF), which quantifies the 'harm per unit effort' that an adversary can inflict on the system. We provide novel, adversarial analysis of WSJF and show that any system using this policy has a worst-case DF of only a small constant, where traditional schedulers place no upper bound on the DF. Illustrating that SurgeProtector is not only theoretically, but practically robust, we integrate SurgeProtector into an open source intrusion detection system (IDS). Under simulated attack, the SurgeProtector-augmented IDS suffers 90--99% lower innocent traffic loss than the original system.