教学文库网 - 权威文档分享云平台
您的当前位置:首页 > 文库大全 > 专业资料 >

Abstract Detecting DDoS Attacks on ISP Networks

来源:网络收集 时间:2026-09-16
导读: Most past solutions for detecting denial of service attacks (and identifying the perpetrators) have targeted end-node victims. However, little attention has been given to this problem from an ISP perspective. This paper explores the key ch

Most past solutions for detecting denial of service attacks (and identifying the perpetrators) have targeted end-node victims. However, little attention has been given to this problem from an ISP perspective. This paper explores the key challenges involved

DetectingDDoSAttacksonISPNetworks

AdityaAkella

AshwinBharambe

MikeReiter

SrinivasanSeshan

CarnegieMellonUniversity

Abstract

Mostpastsolutionsfordetectingdenialofserviceattacks(andiden-tifyingtheperpetrators)havetargetedend-nodevictims.However,littleattentionhasbeengiventothisproblemfromanISPperspec-tive.ThispaperexploresthekeychallengesinvolvedinhelpinganISPnetworkdetectattacksonitselforattacksonexternalsiteswhichusetheISPnetwork.Weproposeadetectionmechanismwhereeachrouterdetectstraf canamoliesusingpro lesofnormaltraf cconstructedusingstreamsamplingalgorithms.Inaddition,anISP’sroutersexchangeinformationwitheachothertoincreasecon denceintheirdetectiondecisions.Ourinitialresultsshowthatinpidualrouterpro lescapturekeycharacteristicsofthetraf ceffectivelyandhelpidentifyanomalieswithlowfalsepositiveandfalsenegativerates.Webelievethatpro leconstructioncanbeex-tremelyef cient,supportingevenmulti-gigabitspeeds.Wealsobe-lievethatincrementaldeploymentofsuchtechniquesispossible,althoughitmaysign cantlyimpacttheeffectivenessofthedis-tributedreinforceddecisionmaking.

1Introduction

DistributedDenialofService(DDoS)attackshavebecomeanin-creasinglyfrequentdisturbanceintoday’sInternet.Manyrecentre-searcheffortshaveexploreddesigningmechanismsfordetectingsuchattacksandidentifyingtheperpetrators.However,alltheseso-lutionsareaimedataidingend-nodevictimsunderattack.Inthiswork,welookattheproblemfromthepointofviewofanInternetServiceProvider(ISP).Speci cally,wedesignmechanismsthatal-lowISPstoquicklyandef cientlyanswerthefollowingquestions:(1)IstheISPbackboneitselfunderaDDoSattack?(2)IstheISPnetworkcarryingmuch“useless”1traf c?(3)Whichtraf cisma-liciousandwhatshouldbedonetosuchtraf c?

Intoday’sBGP-drivenInternet,largeASespeerwithotherASesatmultiplePoPs(PointsofPresence).Ifapacket’sdestinationisnotwithinitself,anAShandsoverthepackettootherASesassoonaspossible.Thishotpotatoroutingmaynotusetheshortestroutetothedestination.Duetothesefactors,packetsgoingtothesamedestinationcantraverseperseanddisjointpathsthroughanAS.This“dispersion”makesithardtodetectDDoStraf catanysinglepoint,necessitatingadistributedapproachtotheproblem.OurapproachtothisproblemreliesonrouterswithintheISPiden-tifyingtraf cpatternviolationsthemselves.Thisisachievedbybuildingtraf cpro lesusingstreamsamplingalgorithmswhichhaveanextremelysmallmemoryfootprint.Bysamplingoverrela-tivelylongtimewindows,normaltraf cpro lesarecreatedwhilecurrenttraf cpro lesareconstructedbyusingsmallertimewin-dows.Wheneverthecurrentpro ledoesnotcorroboratewiththe

Most past solutions for detecting denial of service attacks (and identifying the perpetrators) have targeted end-node victims. However, little attention has been given to this problem from an ISP perspective. This paper explores the key challenges involved

Forvariousvalueof,thenumberof/pre xessourcingtraf- ctothedestination.Themotivationisthatthissetof n-gerprintscharacterizessource-subnetdistributionandwouldcatchrandomsourcespoo ngbyanattacker.

Anapproximationtothe ow-lengthdistributionoftraf ctothedestination.Wesamplespeci cpointsonthe ow-lengthdistributionbykeepingtrackofthenumberofsourceIPad-dressesthatsendmorethanfractionofthetotaltraf ctothedestination,forvariousvaluesof.

suchamessage,theneighborsdiscardduplicates,computetheag-ofthevaluesreceivedperdestinationandfor-gregate,

wardnon-duplicatesalongtotheirneighbors.If,foranydestina-tion,exceedsapre-de nedthreshold,therouterconcludesthatthedestinationisunderattack.This“consensus”stagehelpsreducetheerrorsinidenti cationofattacksevenfurther.Thesemessagescouldbesentusingspeciallow-bandwidthout-of-bandICMPmessagesbetweenrouters.Thesemessagesbetweenneigh-borscanbeauthenticatedwiththeuseofaTTLof255,asin[3]andaretimedoutperiodically(everyminute)unlessrefreshed.

Weusesample-and-hold[2]andzeroethmoment()computation

[4,1]algorithmsforcomputingthese ngerprints.Eachstatisticiscomputedbysamplingoverasmallintervaloftime,aboutaminute.Tore ectthetypicalday-of-weekandhour-of-daytraf cpatterns,routersconstructper-hour,per-weekdaynormaltraf cpro lesbyaveragingthestatisticsoverhourlyperiods.

AlgorithmatEachRouter.Withthesestatisticsinhand,eachrouterusesthefollowingalgorithmforapopulardestination:

1.Letbethenumberofbytestothedestinationinthebase-pro leandbethesamestatisticincurrentsamplinginterval.

,continuetonextstep.Otherwise,stop.If

2.Foreach ngerprint,letdenotethevaluecomputedin

thecurrentsamplinginterval.Letanddenotethemeanandstandarddeviationvaluesforthis ngerprint.2If

,then,else.is

aparametertothealgorithm.

denotethecon dencewithwhichtheroutersus-3.Let

pectsanattack.Weset.as-signs“weights”toa ngerprint,dependingontheextenttowhichthat ngerprintcontributestoerrors(false-positiveornegatives):

PreliminaryResults.Weprovideabriefsetofresultsregardinglo-calpro leconstructionandattackdetectionfunctionalitydescribed

above.Weusetraf cgeneratedbypopularattacktoolslikeTFNandTrin00alongwithtraf ctracesfromAbilenebackboneroutersinNS-2,varyingthenumberofspoofedbytesinsourceIPsandtheat-tackrateagainstdestinationsofdifferentlevelsofpopularity.Ourresultsshowthatthepro lesgeneratedbyoursamplingschemesareverystableandaccurateacrosstimeoveronehourperiods.The ngerprintingschemesalsohaveaverylowfalsepositiverate(weuse)ofabout2%forunpopulardestinationsandabout6%forpopulardestinations.Inaddition,forunpopulardestinations,irrespectiveofthenumberofspoofedoctetsortherate(“reason-ably”high)ofattacktraf c,thefalsenegativerateisclosetozero.Forpopulardestinations,thefalsenegativerateisabout20%forlow-rate,yetsigni cant,attacksbutimprovesrapidlyastherateoft …… 此处隐藏:6752字,全部文档内容请下载后查看。喜欢就下载吧 ……

Abstract Detecting DDoS Attacks on ISP Networks.doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
本文链接:https://www.jiaowen.net/wenku/1759430.html(转载请注明文章来源)
Copyright © 2020-2025 教文网 版权所有
声明 :本网站尊重并保护知识产权,根据《信息网络传播权保护条例》,如果我们转载的作品侵犯了您的权利,请在一个月内通知我们,我们会及时删除。
客服QQ:78024566 邮箱:78024566@qq.com
苏ICP备19068818号-2
Top
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)