pTCP: A Client Puzzle Protocol For Defending Against Resource Exhaustion Denial of Service Attacks
Timothy J. McNevin, Jung-Min Jerry Park, Randolph C. Marchany · 2004
Over the past few years, denial of service (DoS) attacks have become more of a threat than ever. DoS attacks are aimed at denying or degrading service for a legitimate user by exhausting the resources for a particular system. Client puzzle protocols have received attention in recent years as a method for combating DoS attacks. In a client puzzle protocol, the client is forced to solve a cryptographic puzzle before it can establish a connection with a remote server. This paper introduces a novel client puzzle protocol that utilizes a modification of the Extended Tiny Encryption Algorithm. An implementation of the client puzzle protocol was completed in the TCP stack of the Mandrake Linux 9.2 operating system. We call this modification to the TCP stack pTCP (for Puzzle TCP). Our client puzzle algorithm is very fast, and is portable to other systems and architectures. More importantly, it is very effective against connection depletion DoS attacks and other resource exhaustion DoS attacks (on the server) because minimal computation load is imposed on the server to verify the solution to a given puzzle. Our client puzzle protocol is also effective against various other resource exhaustion attacks within the transport layer, and can help prevent attacks that exist at the application layer. In this paper, we describe our client puzzle protocol in detail, and show its effectiveness against DoS attacks by using experimental results.