Sciweavers

CCR
2007

An edge-to-edge filtering architecture against DoS

13 years 11 months ago
An edge-to-edge filtering architecture against DoS
Defending against large, distributed Denial-of-Service attacks is challenging, with large changes to the network core or to end-hosts often suggested. To make matters worse, spoofing adds to the difficulty, since defenses must resist attempts to trigger filtering of other people’s traffic. Further, any solution has to provide incentives for deployment, or it will never see the light of day. We present a simple and effective architectural defense against distributed DoS attacks that requires no changes to the end-hosts, minimal changes to the network core, is robust to spoofing, provides incentives for initial deployment, and can be built with offthe-shelf hardware. Categories and Subject Descriptors C.2.1 [Computer Communication Networks]: [Network Architecture and Design] General Terms Design, Security Keywords Denial-of-service, Internet Architecture
Felipe Huici, Mark Handley
Added 12 Dec 2010
Updated 12 Dec 2010
Type Journal
Year 2007
Where CCR
Authors Felipe Huici, Mark Handley
Comments (0)