Controlling high bandwidth aggregates in the network
Top Cited Papers
- 1 July 2002
- journal article
- Published by Association for Computing Machinery (ACM) in ACM SIGCOMM Computer Communication Review
- Vol. 32 (3) , 62-73
- https://doi.org/10.1145/571697.571724
Abstract
The current Internet infrastructure has very few built-in protection mechanisms, and is therefore vulnerable to attacks and failures. In particular, recent events have illustrated the Internet's vulnerability to both denial of service (DoS) attacks and flash crowds in which one or more links in the network (or servers at the edge of the network) become severely congested. In both DoS attacks and flash crowds the congestion is due neither to a single flow, nor to a general increase in traffic, but to a well-defined subset of the traffic --- an aggregate . This paper proposes mechanisms for detecting and controlling such high bandwidth aggregates. Our design involves both a local mechanism for detecting and controlling an aggregate at a single router, and a cooperative pushback mechanism in which a router can ask upstream routers to control an aggregate. While certainly not a panacea, these mechanisms could provide some needed relief from flash crowds and flooding-style DoS attacks. The presentation in this paper is a first step towards a more rigorous evaluation of these mechanisms.Keywords
This publication has 15 references indexed in Scilit:
- Controlling high bandwidth aggregates in the networkACM SIGCOMM Computer Communication Review, 2002
- Flash crowds and denial of service attacksPublished by Association for Computing Machinery (ACM) ,2002
- An analysis of using reflectors for distributed denial-of-service attacksACM SIGCOMM Computer Communication Review, 2001
- Practical network support for IP tracebackPublished by Association for Computing Machinery (ACM) ,2000
- Denial-of-service attacks rip the internetComputer, 2000
- Resource pricing and the evolution of congestion controlAutomatica, 1999
- Promoting the use of end-to-end congestion control in the InternetIEEE/ACM Transactions on Networking, 1999
- Core -stateless fair queueingPublished by Association for Computing Machinery (ACM) ,1998
- Dynamics of random early detectionPublished by Association for Computing Machinery (ACM) ,1997
- Link-sharing and resource management models for packet networksIEEE/ACM Transactions on Networking, 1995