Ensuring QoS During Bandwidth DDoS Attacks
Moti Geva · 2013
Distributed Denial of Service (DDoS) attacks are aimed at exhausting various resources of victim hosts, thereby preventing legitimate usage of their computational capabilities. DDoS attacks are often launched by organized crime, hacktivists, or other (un)usual suspects, making this type of cyber crime a major concern for many organizations around the world. The Internet is a best-effort packet-switching network. Everyday usage shows that the Internet is able to properly work, and successfully deliver information across the globe in an instant. However, bandwidth distributed denial of service (BW-DDoS) attacks bring to light the limitations of best-effort networks. In this thesis we present our research about mitigation of Bandwidth DDoS (BWDDoS) attacks. BW-DDoS is aimed at exhausting network resources, commonly routers’ queue space, and prevent access to the victim server. BW-DDoS attacks have a devastating effect over protocols employing congestion control, as their performance is sharply degraded as a result of losses and delays. BW-DDoS mitigation techniques introduced in this work refrain from making changes to Internet infrastructure equipment, i.e. routers, hence they are focused on adjusting end-host behavior, and the configuration of routers. The first chapter serves as an introduction to this work. In it we overview key BWDDoS attacks and defenses. We argue that so far, BW-DDoS has employed relatively crude, inefficient, “brute force” mechanisms; future attacks may be significantly more effective, and hence much more harmful. We discuss current deployed and proposed defenses. We argue that to meet the increasing threats, more advanced defenses should