A moving target defense approach to mitigate DDoS attacks against proxy-based architectures

A moving target defense approach to mitigate DDoS attacks against proxy-based architectures
复制标题

一种移动目标防御方法,可减轻针对基于代理的架构的 DDoS 攻击

DOI:
--
复制
发表时间:
2016
期刊:
IEEE Conference on Communications and Network Security
影响因子:
--
通讯作者:
Mason Wright
Mason Wright
中科院分区:
--
文献类型:
--
作者:
S. Venkatesan;Massimiliano Albanese;Kareem Amin;S. Jajodia;Mason Wright

文献摘要

被引文献

相似文献

近年来,针对知名目标的分布式拒绝服务攻击变得更加频繁。为了应对如此大规模的攻击,一些体系结构已经采用代理来在最终用户和目标服务之间引入间接层,并通过将用户迁移到新的代理并在代理之间洗牌客户端来隔离恶意客户端来减少DDoS攻击的影响。然而,这些解决方案的反应性带来了弱点,我们利用这些弱点开发了一种新的攻击-代理获取攻击-使恶意客户端能够在发起DDoS攻击之前收集有关大量代理的信息。提出了一种移动目标防御技术,即周期性地主动替换一个或多个代理,并将客户重新映射到代理。我们的主要目标是破坏袭击者的侦察行动。此外,为了缓解持续的攻击,我们提出了一种新的客户端到代理分配策略来隔离受攻击的客户端,从而减少攻击的影响。我们从理论和仿真两个方面对我们的方法进行了验证,并表明所提出的解决方案可以有效地限制攻击者可以发现和隔离的恶意客户端的代理数量。
Distributed Denial of Service attacks against high-profile targets have become more frequent in recent years. In response to such massive attacks, several architectures have adopted proxies to introduce layers of indirection between end users and target services and reduce the impact of a DDoS attack by migrating users to new proxies and shuffling clients across proxies so as to isolate malicious clients. However, the reactive nature of these solutions presents weaknesses that we leveraged to develop a new attack - the proxy harvesting attack - which enables malicious clients to collect information about a large number of proxies before launching a DDoS attack. We show that current solutions are vulnerable to this attack, and propose a moving target defense technique consisting in periodically and proactively replacing one or more proxies and remapping clients to proxies. Our primary goal is to disrupt the attacker's reconnaissance effort. Additionally, to mitigate ongoing attacks, we propose a new client-to-proxy assignment strategy to isolate compromised clients, thereby reducing the impact of attacks. We validate our approach both theoretically and through simulation, and show that the proposed solution can effectively limit the number of proxies an attacker can discover and isolate malicious clients.