EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
批准号:
1741608
负责人:
Roberto Perdisci
金额:
$17.98万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2021-07-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Large-scale distributed denial of service (DDoS) attacks pose an imminent threat to the availability of critical Internet-based operations, as demonstrated by recent incidents that brought down a number of highly popular web services such as Twitter, Spotify and Reddit. While several solutions to counter DDoS attacks have been proposed by both industry and academia, most of the solutions that are currently deployed on the Internet - such as traffic scrubbing - tend to detect and mitigate DDoS attacks close to the victim edge network, once the attack has already caused damage. Creating systems for early DDoS attack detection and mitigation that can be deployed at the core of the Internet has the potential to significantly improve Internet security and reliability. This project investigates innovative machine learning-based DDoS attack detection and mitigation solutions that can be deployed at the core of the Internet, within Internet eXchange Points (IXPs). IXPs are high-density peering hubs that provide infrastructure used by autonomous systems (ASes) to interconnect, and are therefore well positioned to observe significant fractions of global Internet traffic. The project leverages IXP-based traffic monitoring to develop advanced traffic analysis and classification methods for efficient, automated early detection and mitigation of DDoS attacks. The researchers aim to first investigate methods for defending against distributed reflective DoS (DRDoS) attacks, which rely on spoofed IP traffic to amplify the attacker's available bandwidth, and to then expand the investigation to volumetric DDoS attacks that do not rely on spoofed traffic. As part of the project, the researchers aim to develop collaborations with IXPs and Internet operators around the world, to facilitate research on DDoS defenses and increase opportunities for high-impact technology transfer.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Detecting and Measuring In-The-Wild DRDoS Attacks at IXPs
检测和测量 IXP 上的野外 DRDoS 攻击
DOI:
10.1007/978-3-030-80825-9_3
发表时间:
2021
期刊:
and Vulnerability Assessment
影响因子:
--
作者:
[Subramani, Karthika, Perdisci, Roberto, Konte, Maria]
通讯作者:
Konte, Maria
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
-
批准号:2126641
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Roberto Perdisci
-
依托单位:
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
-
批准号:1514052
-
项目类别:Standard Grant
-
资助金额:$29.99万
-
财政年份:2015
-
负责人:Roberto Perdisci
-
依托单位:
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
-
批准号:1149051
-
项目类别:Continuing Grant
-
资助金额:$40.26万
-
财政年份:2012
-
负责人:Roberto Perdisci
-
依托单位:
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
-
批准号:1127195
-
项目类别:Standard Grant
-
资助金额:$38.0万
-
财政年份:2011
-
负责人:Roberto Perdisci
-
依托单位:
海外基金