Avoiding DDoS with active management of backlog queues

Martine Bellaïche, Jean‐Charles Grégoire · 2011

TCP (Transmission Control Protocol) is the dominant end to end transport protocol of the Internet, with a wide range of applications including Web, mail or peer to peer traffic. The TCP stack implements a “backlog queue” for new connections, which contains an entry for every client's connection setup received by the server. If the TCP handshake is not completed, the pending half-open connection stays in the backlog queue until a time-out expires and, if that time-out value is too big, the half-open connection stays in the queue longer than necessary. We present a technique to assign and find a suitable connection-establishment time-out value to reduce the risks of an overflow of the backlog queue in situations of SYN flooding attacks. We evaluate from experimental traces that our technique can reduce the size of the backlog queue size up to 50% while preserving normal connections.

Read the paper · More papers on PaperTik