课题基金 / 基金详情

EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks

EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
EAGER:协作:利用高密度互联网对等中心缓解大规模 DDoS 攻击
批准号:
1741608
负责人:
Roberto Perdisci
金额:
$17.98万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2021-07-31

项目摘要

项目成果

Roberto Perdisci的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Large-scale distributed denial of service (DDoS) attacks pose an imminent threat to the availability of critical Internet-based operations, as demonstrated by recent incidents that brought down a number of highly popular web services such as Twitter, Spotify and Reddit. While several solutions to counter DDoS attacks have been proposed by both industry and academia, most of the solutions that are currently deployed on the Internet - such as traffic scrubbing - tend to detect and mitigate DDoS attacks close to the victim edge network, once the attack has already caused damage. Creating systems for early DDoS attack detection and mitigation that can be deployed at the core of the Internet has the potential to significantly improve Internet security and reliability. This project investigates innovative machine learning-based DDoS attack detection and mitigation solutions that can be deployed at the core of the Internet, within Internet eXchange Points (IXPs). IXPs are high-density peering hubs that provide infrastructure used by autonomous systems (ASes) to interconnect, and are therefore well positioned to observe significant fractions of global Internet traffic. The project leverages IXP-based traffic monitoring to develop advanced traffic analysis and classification methods for efficient, automated early detection and mitigation of DDoS attacks. The researchers aim to first investigate methods for defending against distributed reflective DoS (DRDoS) attacks, which rely on spoofed IP traffic to amplify the attacker's available bandwidth, and to then expand the investigation to volumetric DDoS attacks that do not rely on spoofed traffic. As part of the project, the researchers aim to develop collaborations with IXPs and Internet operators around the world, to facilitate research on DDoS defenses and increase opportunities for high-impact technology transfer.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Detecting and Measuring In-The-Wild DRDoS Attacks at IXPs
检测和测量 IXP 上的野外 DRDoS 攻击
DOI: 10.1007/978-3-030-80825-9_3
发表时间: 2021
期刊: and Vulnerability Assessment
影响因子: --
作者: [Subramani, Karthika, Perdisci, Roberto, Konte, Maria]
通讯作者: Konte, Maria
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
海外基金