Context Matters: Accurately Measuring the Efficacy of Denial-of-Service Mitigations
Samuel DeLaughter, Karen R. Sollins · 2022
Denial-of-Service (DoS) attacks remain a severe and constant threat to the Internet. While various mitigation strategies have been developed and deployed to defend against these attacks, the community lacks adequate metrics for quantifying their efficacy. Metrics used to quantify DoS attacks provide a solid starting point, but extending them to the domain of mitigations is non-trivial. Current metrics don’t account for a mitigation’s overhead outside periods of attack, and fail to capture important context – differences in attack rate, client behavior, network topology, and various other factors can all dramatically alter the impact of attacks and the efficacy of mitigations. This paper provides a methodology and novel suite of metrics designed to enable more meaningful and contextual measurement of DoS mitigations. To illustrate the benefits of these metrics we conduct experiments in the DeterLab network testbed measuring the efficacy of SYN Cookies, a well-known and widely used mitigation against the ubiquitous TCP SYN flood attack. We show that this mitigation is highly effective in certain contexts but can significantly degrade client quality of service in others. Our goal is to help device owners and network operators determine which mitigations are best suited for their particular context, and to help protocol designers and implementers develop a more DoS-resilient Internet.