On Defending Against Distribtued Denial- of-Service Attacks with Server-Centric Router Throttles

David K. Y. Yau, Feng Liang, John C. S. Lui · Purdue e-Pubs (Purdue University System) · 2001

We present a network architecture and accompanying algoril.hmsfor countering distributed denial-of-service (ODaS) atlacks directed at an Internet server.The basic mechanism is for a server under stress 10 inslall a router throttle at selected up-Slream routers.The throttle is the leaky-bucket rate at which a router can forward packets destined for the server.Hence, before aggressive packets can converge to overwhelm the server, participating rou tees proactively regulate the contributing packet rates to more moderate levels, thus forstalling an impending atlack.In allocating the server capacity among the roulers, we propose a notion of fevel-k max-minfaimess.Wc present simulation results using a realistic global network topology, and various models of good uscr and atlacker distributions and behaviors.Using a generator model of web requests parameterized by empirical data, we also evaluate Ihe impact of throtUing in protecting user access to a web server.First, for aggressive attackers, the throttle mechanism is highly effective in preferentially dropping atlaeker traffic over good user traffic.In particular, level-k max-min fairness gives bener good-user protection than recursive pushback of max-min fair ratc limits proposed in the literature.Second, throlUing can regulate the experienced scrver load to below its design limit -in Ihe presence of user dynamics -so that the server can remain operational during a DDoS attack.

Read the paper · More papers on PaperTik