A Proactive Approach to Distributed DoS Prevention Using Route-Based Packet Filtering

Ki‐Hong Park, Heejo Lee · Purdue e-Pubs (Purdue University System) · 2000

Denial-of-service (DoS) attack on the Internet has become a pressing problem.I11 this paper, we describe.analyze and evaluate route-based distributed packet filtering (DPF).a n o ~e l approach t o distributed DoS (DDoS) attack prevention.\Ve show that there is an intimate relationsliip between the effectiveness of D P F a t mitigating DDoS attacks and power-law network tol~ology.We evaluate performance using Internet autonoinous system and artificially generated topologies.T h e sa.lient features of this work are t~vo-fold.First.we show that D P F is able t o proactively filter out a significant fraction of spoofed pacltet flows and prevent attack packets froill reaching their targets in the first place.The IP flo~vs that cannot be proactively curtailed are extremely sparse such that their origin ca.n be localized-i.e..I P tra.ceback-to a:it,l~in a small.constant number of candidate sites.\Ve show that the two proactive and reactive performance effects can be achieved by implementing route-based filtering on less than 20% of lnt,ernet autonomous system (AS) sites.Second, we show t h a t the two complelnentary performance measures are dependent on the properties of the underlying AS graph topology.In particular.we sho~v that the power-law structure of Internet AS topology leads t o connectivity properties which are crucial in facilitating the observed performance effects.-4s a DDoS prevention architecture.D P F is able to emulate the I P traceback pronjess of probabilistic packet marking, while a.lleviating the la.tt,er's three principal lveaknesses: (i) need to inscribe link information in the I P pacltet header.(ii) rea~t~ireness-tracebaclt occurs after the impact of DoS attack has been felt-and (iii) scalability where t,he effort needed t o achieve I P ti-aceback grows proportionally \vit,h the number of attack hosts engaged in a DDoS attack.-----'This work w;is

Read the paper · More papers on PaperTik