Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Journal articles
  4. Scalable Network-layer Defense Against Internet Bandwidth-Flooding Attacks
 
research article

Scalable Network-layer Defense Against Internet Bandwidth-Flooding Attacks

Argyraki, Katerina  
•
Cheriton, David R.
2009
IEEE/ACM Transactions on Networking

In a bandwidth-flooding attack, compromised sources send high-volume traffic to the target with the purpose of causing congestion in its tail circuit and disrupting its legitimate communications. In this paper, we present Active Internet Traffic Filtering (AITF), a network-layer defense mechanism against such attacks. AITF enables a receiver to contact misbehaving sources and ask them to stop sending it traffic; each source that has been asked to stop is policed by its own Internet service provider (ISP), which ensures its compliance. An ISP that hosts misbehaving sources either supports AITF (and accepts to police its misbehaving clients), or risks losing all access to the complaining receiver---this is a strong incentive to cooperate, especially when the receiver is a popular public-access site. We show that AITF preserves a significant fraction of a receiver's bandwidth in the face of bandwidth flooding, and does so at a per-client cost that is already affordable for today's ISPs; this per-client cost is not expected to increase, as long as botnet-size growth does not outpace Moore's law. We also show that even the first two networks that deploy AITF can maintain their connectivity to each other in the face of bandwidth flooding. We conclude that the network-layer of the Internet can provide an effective, scalable, and incrementally deployable solution against bandwidth-flooding attacks.

  • Files
  • Details
  • Metrics
Type
research article
DOI
10.1109/TNET.2008.2007431
Web of Science ID

WOS:000269155300021

Author(s)
Argyraki, Katerina  
Cheriton, David R.
Date Issued

2009

Published in
IEEE/ACM Transactions on Networking
Volume

17

Issue

4

Start page

1284

End page

1297

Subjects

Denial-of-service

•

Bandwidth flooding

•

Filtering

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
NAL  
Available on Infoscience
September 30, 2008
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/30004
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés