DDD: A DNS-based DDoS Defense Scheme Using Puzzles
Hyeonmin Lee, Taehyun Kang, Sukhun Yang, Jinyong Jun, Taekyoung Kwon · 2024
Distributed Denial-of-Service (DDoS) attacks have remained a significant threat to the Internet for years. One strategy for mitigating these attacks involves requiring clients to solve cryptographic puzzles to control the rate of incoming traffic to a target server. For such a puzzle-based DDoS defense mechanism to be effective, it necessitates robust methods for both distributing puzzles to clients and adjusting puzzle difficulty. In this paper, we introduce a puzzle-based DDoS defense mechanism, DDD, which utilizes the Domain Name System (DNS) for distributing puzzles to clients. The target server disseminates its puzzles by publishing them as a DNS record through its authoritative name server, distributing puzzles to clients via their DNS resolvers. Our design incorporates a monitoring server that continuously monitors incoming traffic to the target and dynamically adjusts puzzle difficulty based on the traffic originating afrom each Autonomous System (AS). This enables AS-specific puzzle difficulty customization, and consequently, traffic control. We have implemented our design into the Linux kernel and showcased its effectiveness in traffic control through prototype-based and controlled experiments.