首页> 外文期刊>International Journal of Information Security >A multi-layer framework for puzzle-based denial-of-service defense
【24h】

A multi-layer framework for puzzle-based denial-of-service defense

机译:基于难题的拒绝服务防御的多层框架

获取原文
获取原文并翻译 | 示例
           

摘要

Client puzzles have been advocated as a promising countermeasure to denial-of-service (DoS) attacks in recent years. However, how to operationalize this idea in network protocol stacks still has not been sufficiently studied. In this paper, we describe our research on a multi-layer puzzle-based DoS defense architecture, which embeds puzzle techniques into both end-to-end and IP-layer services. Specifically, our research results in two new puzzle techniques: puzzle auctions for end-to-end protection and congestion puzzles for IP-layer protection. We present the designs of these approaches and evaluations of their efficacy. We demonstrate that our techniques effectively mitigate DoS threats to IP, TCP and application protocols; maintain full interoperability with legacy systems; and support incremental deployment. We also provide a game theoretic analysis that sheds light on the potential to use client puzzles for incentive engineering: the costs of solving puzzles on an attackers' behalf could motivate computer owners to more aggressively cleanse their computers of malware, in turn hindering the attacker from capturing a large number of computers with which it can launch DoS attacks.
机译:近年来,客户困惑一直被认为是拒绝服务(DoS)攻击的有希望的对策。但是,如何在网络协议栈中实现这一思想还没有得到足够的研究。在本文中,我们描述了我们对基于拼图的多层DoS防御体系结构的研究,该体系结构将拼图技术嵌入到端到端和IP层服务中。具体来说,我们的研究产生了两种新的拼图技术:用于端到端保护的拼图拍卖和用于IP层保护的拥塞拼图。我们介绍了这些方法的设计及其效果评估。我们证明了我们的技术可以有效缓解对IP,TCP和应用协议的DoS威胁;保持与遗留系统的完全互操作性;并支持增量部署。我们还提供了一种博弈论分析,阐明了使用客户端难题进行激励工程的潜力:以攻击者的名义解决难题的成本可能会促使计算机所有者更积极地清理其恶意软件,从而阻碍了攻击者捕获大量可以发起DoS攻击的计算机。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号