A DoS-limiting network architecture
- 22 August 2005
- journal article
- Published by Association for Computing Machinery (ACM) in ACM SIGCOMM Computer Communication Review
- Vol. 35 (4) , 241-252
- https://doi.org/10.1145/1090191.1080120
Abstract
We present the design and evaluation of TVA, a network architecture that limits the impact of Denial of Service (DoS) floods from the outset. Our work builds on earlier work on capabilities in which senders obtain short-term authorizations from receivers that they stamp on their packets. We address the full range of possible attacks against communication between pairs of hosts, including spoofed packet floods, network and host bottlenecks, and router state exhaustion. We use simulation to show that attack traffic can only degrade legitimate traffic to a limited extent, significantly outperforming previously proposed DoS solutions. We use a modified Linux kernel implementation to argue that our design can run on gigabit links using only inexpensive off-the-shelf hardware. Our design is also suitable for transition into practice, providing incremental benefit for incremental deployment.Keywords
This publication has 11 references indexed in Scilit:
- Steps towards a DoS-resistant internet architecturePublished by Association for Computing Machinery (ACM) ,2004
- SIFF: a stateless internet flow filter to mitigate DDoS flooding attacksPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2004
- A scalable and robust solution for bandwidth allocationPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- SOSPublished by Association for Computing Machinery (ACM) ,2002
- Controlling high bandwidth aggregates in the networkACM SIGCOMM Computer Communication Review, 2002
- Hash-based IP tracebackPublished by Association for Computing Machinery (ACM) ,2001
- Practical network support for IP tracebackPublished by Association for Computing Machinery (ACM) ,2000
- The click modular routerACM Transactions on Computer Systems, 2000
- Core -stateless fair queueingPublished by Association for Computing Machinery (ACM) ,1998
- Lazy receiver processing (LRP)Published by Association for Computing Machinery (ACM) ,1996