A novel framework for modeling and mitigating distributed link flooding attacks

A novel framework for modeling and mitigating distributed link flooding attacks
复制标题

DOI:
10.1109/infocom.2016.7524507
复制
发表时间:
2016-04
期刊:
IEEE INFOCOM 2016 - The 35th Annual IEEE International Conference on Computer Communications
影响因子:
--
通讯作者:
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos
中科院分区:
其他
文献类型:
--
作者:
C. Liaskos;Vasileios Kotronis;X. Dimitropoulos

文献摘要

被引文献

相似文献

分布式链接洪泛攻击构成了一种新的攻击类别,有可能分割互联网的大片区域。它们的分布性使得检测和缓解非常困难。这项工作为此类攻击的分析建模和最优缓解提出了一个新的框架。该检测被建模为一个关系代数问题,表示潜在攻击者(机器人)与潜在目标的关联。这项分析寻求以最佳方式消除除恶意联想以外的所有联想。该框架是在在线流量工程(TE)级别实现的,该流量工程在链路泛洪事件时自然触发。其关键思想是以一种使任何良性来源都不太可能持续参与链路泛洪事件的方式持续地重新路由流量。因此,机器人被迫采取可疑行为以保持有效性,从而暴露出它们的存在。TE的负载均衡目标完全不受影响。在各种拓扑上的大量模拟验证了我们的分析结果。
Distributed link-flooding attacks constitute a new class of attacks with the potential to segment large areas of the Internet. Their distributed nature makes detection and mitigation very hard. This work proposes a novel framework for the analytical modeling and optimal mitigation of such attacks. The detection is modeled as a problem of relational algebra, representing the association of potential attackers (bots) to potential targets. The analysis seeks to optimally dissolve all but the malevolent associations. The framework is implemented at the level of online Traffic Engineering (TE), which is naturally triggered on link-flooding events. The key idea is to continuously re-route traffic in a manner that makes persistent participation to link-flooding events highly improbable for any benign source. Thus, bots are forced to adopt a suspicious behavior to remain effective, revealing their presence. The load-balancing objective of TE is not affected at all. Extensive simulations on various topologies validate our analytical findings.