CRII: SaTC: Explorng the Real World Applicability of Denial of Service Mitigation via Routing
CRII: SaTC: Explorng the Real World Applicability of Denial of Service Mitigation via Routing
批准号:
1850379
负责人:
Max Schuchard
金额:
$17.49万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-01 至 2021-05-31
中文摘要
分布式拒绝服务(DDoS)攻击通过向受害者发送大量不需要的网络流量,破坏了计算机在互联网上的通信能力。由于其高经济影响和低技术复杂性,此类攻击仍然是公司、组织和知名个人经历过的最有问题和最常见的攻击之一。本研究项目探讨了通过动态调整互联网上的路径流量来减轻分布式拒绝服务攻击影响的可行性,使其避免被攻击流量阻塞的链路。与目前部署的技术相比,该技术具有许多优点,这些技术既昂贵,又在许多情况下无效。该项目的研究还帮助科学家更广泛地了解互联网如何响应按需重新路由的流量。这项研究的最终产品是功能原型系统,能够确保分布式拒绝服务攻击的受害者仍然可以通过互联网进行通信,同时价格低廉,可部署在现有的互联网基础设施上。该项目将训练学生进行研究,并分发软件原型供网络运营商社区使用。它还将努力将研究成果转化为实践。采用这种系统将有助于公司避免分布式拒绝服务攻击带来的财务损失,并保护关键基础设施,例如智能电网和国防通信免受此类攻击。本研究项目扩展了我们对基于重路由的DDoS攻击缓解系统如何在实践中发挥作用的知识。正在进行的实验探索了可行部署这种系统所必需的三个关键领域。首先,研究将验证重路由作为实时互联网安全原语的可行性。为了探索这一点,研究人员试图在互联网上为自己的网络执行重路由策略,从不同的有利位置观察对路径选择的影响。这些实验量化了抑制流量迁移能力的策略的普遍性、实践中可用的替代路径的数量以及这些路径的独立性。其次,研究人员正在探索多个参与者同时成功利用重新路由的可行性。研究人员正在开发算法,计算互联网基础设施可以支持的最大重路由量,并分配这些资源,以最有效地利用这些容量。最后,研究人员正在增强基于重路由的缓解功能,以对抗动态对手。考虑到攻击者重新路由恶意流量的能力,研究人员正在构建替代路径选择策略,以最大限度地减少攻击者违反流量隔离的能力,同时探索通过不断重新路由关键流量使用移动目标防御策略的可行性。该项目产生了基于重新路由的分布式拒绝服务缓解系统的功能软件原型,免费提供给网络运营商社区供其使用。研究人员正在通过与网络运营商社区接触,促进系统向实践的过渡(TTP),既教育他们这种解决方案的可能性,也接受反馈和建议,以改进未来。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Distributed Denial of Service (DDoS) attacks disrupt the ability of computers to communicate over the Internet by flooding victims with large volumes of unwanted network traffic. Due to their high economic impact and low technical complexity, such attacks remain one of the most problematic and common attacks experienced by companies, organizations, and high-profile individuals. This research project explores the viability of mitigating the effects of a distributed denial of service attack by dynamically adjusting the path traffic takes through the Internet, causing it avoid links congested with attack traffic. This technique has a number of advantages over currently deployed techniques which are both costly and, in many instances, ineffective. The research in this project additionally helps scientists more broadly understand how the Internet responds to on-demand re-routing of traffic. The final product of this research is functional prototype systems that are capable of ensuring that victims of a distributed denial of service attack can still communicate over the Internet, while at the same time being inexpensive and deployable on the existing Internet infrastructure. The project will train students in research as well as distribute software prototypes for the network operator community to use. It will also spend efforts to transition research to practice. The adoption of such systems would help companies avoid the financial harm that comes from distributed denial of service attacks and secure critical infrastructures, for example Smart Grids and national defense communications, from such attacks.This research project expands our knowledge of how re-routing based DDoS attack mitigation systems would function in practice. The experiments being conducted explore three key areas necessary for viable deployment of such systems. First, the research would validate the feasibility of re-routing as a security primitive on the live Internet. To explore this, researchers are attempting to execute re-routing policy on the Internet for their own network, observing from diverse vantage points the impact on path selection. These experiments quantify the prevalence of policies that inhibit the ability to migrate traffic, the number of alternative paths available in practice, and the independence of those paths. Second, researchers are exploring the viability of multiple actors successfully utilizing re-routing simultaneously. Researchers are developing algorithms that both compute the maximal amount of re-routing the Internet infrastructure can support and allocate those resources to make the most efficient use of this capacity. Lastly, researchers are enhancing re-routing based mitigation to function against dynamic adversaries. By considering the capacity of adversaries to also re-route their malicious traffic, researchers are building alternative path selection strategies that minimize the ability of the adversary to violate traffic isolation, and at the same time are exploring the viability of using a moving target defensive strategy through continuously re-routing critical traffic. This project results in functional software prototypes of a re-routing based distributed denial of service mitigation system that are freely supplied to the networking operator community for their use. Researchers are facilitating the system's transition to practice (TTP) by reaching out to the network operator community, both educating them on the possibilities of such solutions and as well as receiving feedback and suggestions for future enhancement.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金