Distributed Denial of Service Defense Attack Tradeoff Analysis (DDOS-DATA) Demonstration Overview

W. J. Blackert, D. M. Gregg, A. K. Castner, R.L. Hom, R. M. Jokerst, E.M. Kyle · 2003

Because of their rapidly evolving and increasingly aggressive nature, Denial of Service (DOS) attacks have proved particularly difficult to defend against. In most cases, the defenses have been reactionary and result from ad hoc development of mitigation strategies and technologies. One means to break this reactionary cycle is to develop an understanding of the principles that drive performance of both DOS attacks and mitigation technologies. This approach reveals the fundamental boundaries of DOS attacks and quantifies attack and mitigation performance. With this insight, the development of design principles and accurate predictions of DOS attack capabilities is then possible, leading to resiliency against well-known and novel attacks. Under sponsorship of the Defense Advanced Research Projects Agency’s (DARPA) Fault Tolerant Networks (FTN) program, The Johns Hopkins University Applied Physics Laboratory (JHU/APL) has been conducting the Distributed Denial of Service Defense Attack Tradeoff Analysis (DDOS-DATA). DDOS-DATA uses analysis to understand DDOS attacks, mitigation technologies, and their interaction. Through this effort, we have developed a better understanding of attacker-to-mitigation and mitigation-tomitigation technology dynamics, giving rise to design principles and guidance. When analyzing computer network systems, multiple approaches are available including closed-form analysis, test bed studies, and modeling and simulation. Closed form analysis is the most desirable of these since the resulting formulas and expressions can be quickly examined over multiple scenarios. Computer network system complexities typically rule out all but the simplest closed form analysis. An alternative to closed form analysis is the use of a test bed. While this may be the most desirable means to examine systems, two major factors limit test bed usefulness. The first is the cost and complexity associated with maintaining a test bed facility that can adequately represent a complex system (especially in the case of DDOS). The second is that real devices do not always allow themselves so be tuned in every way an analyst may desire. For example, a router’s forwarding rate is not easily increased. The third approach is modeling and simulation. With modeling and simulation, high fidelity models can be verified and validated allowing accuracy and tuneability without prohibitive cost constraints.

Read the paper · More papers on PaperTik