The Experts below are selected from a list of 4647 Experts worldwide ranked by ideXlab platform
Jun Xu - One of the best experts on this subject based on the ideXlab platform.
-
IP traceback-based intelligent packet filtering: A novel technique for defending against Internet DDoS attacks
Proceedings - International Conference on Network Protocols ICNP, 2008Co-Authors: Minho Sung, Jun XuAbstract:Distributed Denial of Service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS Traffic, thus improving the overall throughput of the Legitimate Traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that, while an attacker will have all the edges on its path marked as "infected," edges on the path of a Legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS Traffic while affecting Legitimate Traffic only slightly. Simulation results based on real-world network topologies all demonstrate that the proposed technique can improve the throughput of Legitimate Traffic by three to seven times during DDoS attacks.
-
sustaining availability of web services under distributed denial of service attacks
IEEE Transactions on Computers, 2003Co-Authors: Jun XuAbstract:The recent tide of Distributed Denial of Service (DDoS) attacks against high-profile web sites demonstrate how devastating DDoS attacks are and how defenseless the Internet is under such attacks. We design a practical DDoS defense system that can protect the availability of web services during severe DDoS attacks. The basic idea behind our system is to isolate and protect Legitimate Traffic from a huge volume of DDoS Traffic when an attack occurs. Traffic that needs to be protected can be recognized and protected using efficient cryptographic techniques. Therefore, by provisioning adequate resource (e.g., bandwidth) to Legitimate Traffic separated by this process, we are able to provide adequate service to a large percentage of clients during DDoS attacks. The worst-case performance (effectiveness) of the system is evaluated based on a novel game theoretical framework, which characterizes the natural adversarial relationship between a DDoS adversary and the proposed system. We also conduct a simulation study to verify a key assumption used in the game-theoretical analysis and to demonstrate the system dynamics during an attack.
-
ip traceback based intelligent packet filtering a novel technique for defending against internet ddos attacks
International Conference on Network Protocols, 2002Co-Authors: Minho Sung, Jun XuAbstract:Distributed denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS Traffic, thus improving the overall throughput of the Legitimate Traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that while an attacker will have all the edges on its path marked as "infected", edges on the path of a Legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS Traffic while affecting Legitimate Traffic only slightly. Simulation results based on real-world network topologies (e.g., Skitter) all demonstrate that the proposed technique can improve the throughput of Legitimate Traffic by 3 to 7 times during DDoS attacks.
Leandros Tassiulas - One of the best experts on this subject based on the ideXlab platform.
-
Sustainability of Service Provisioning Systems Under Stealth DoS Attacks
IEEE Transactions on Control of Network Systems, 2017Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We model a service provisioning system under attack by malicious intruders. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake requests attempting to degrade service provisioning—the fake Traffic is assumed low rate and, thus, it is practically undetectable. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed throughput region , that is, the Legitimate Traffic intensities that are guaranteed to be supported given specific intensities of the fake Traffic. The result is first obtained under the assumption that fake Traffic is routed using any static routing. Then, we relax this assumption allowing time-varying attacks. We show that depending on the resources of the malicious attacker and by the use of nonstationary attack policies, some of the servers are effectively neutralized and the guaranteed throughput is greatly compromised. We further examine the interaction between specific policies and encounter interesting phenomena, such as the Join-the-Shortest-Queue not being a maximally stable defense policy under specific time-varying attacks. The study offers defense insights, how to design the system, and how to balance the Traffic to sustain such attacks.
-
Sustainability of service provisioning systems under attack
ACM SIGMETRICS Performance Evaluation Review, 2013Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We propose a resource allocation model that captures the interaction between Legitimate users of a distributed service provisioning system with malicious intruders attempting to disrupt its operation. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake Traffic to the servers attempting to degrade service provisioning. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed region, i.e. the set of Legitimate Traffic intensities that are sustainable given specific intensities of the fake Traffic, under the assumption that the fake Traffic is routed using static policies. This assumption will be relaxed, allowing arbitrary routing policies, in the full version of this work
-
SIGMETRICS - Sustainability of service provisioning systems under attack
Proceedings of the ACM SIGMETRICS international conference on Measurement and modeling of computer systems - SIGMETRICS '13, 2013Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We propose a resource allocation model that captures the interaction between Legitimate users of a distributed service provisioning system with malicious intruders attempting to disrupt its operation. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake Traffic to the servers attempting to degrade service provisioning. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed region, i.e. the set of Legitimate Traffic intensities that are sustainable given specific intensities of the fake Traffic, under the assumption that the fake Traffic is routed using static policies. This assumption will be relaxed, allowing arbitrary routing policies, in the full version of this work.
Minho Sung - One of the best experts on this subject based on the ideXlab platform.
-
IP traceback-based intelligent packet filtering: A novel technique for defending against Internet DDoS attacks
Proceedings - International Conference on Network Protocols ICNP, 2008Co-Authors: Minho Sung, Jun XuAbstract:Distributed Denial of Service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS Traffic, thus improving the overall throughput of the Legitimate Traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that, while an attacker will have all the edges on its path marked as "infected," edges on the path of a Legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS Traffic while affecting Legitimate Traffic only slightly. Simulation results based on real-world network topologies all demonstrate that the proposed technique can improve the throughput of Legitimate Traffic by three to seven times during DDoS attacks.
-
ip traceback based intelligent packet filtering a novel technique for defending against internet ddos attacks
International Conference on Network Protocols, 2002Co-Authors: Minho Sung, Jun XuAbstract:Distributed denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS Traffic, thus improving the overall throughput of the Legitimate Traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that while an attacker will have all the edges on its path marked as "infected", edges on the path of a Legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS Traffic while affecting Legitimate Traffic only slightly. Simulation results based on real-world network topologies (e.g., Skitter) all demonstrate that the proposed technique can improve the throughput of Legitimate Traffic by 3 to 7 times during DDoS attacks.
-
ICNP - IP traceback-based intelligent packet filtering: a novel technique for defending against Internet DDoS attacks
10th IEEE International Conference on Network Protocols 2002. Proceedings., 1Co-Authors: Minho SungAbstract:Distributed denial of service (DDoS) is one of the most difficult security problems to address. While many existing techniques (e.g., IP traceback) focus on tracking the location of the attackers after-the-fact, little is done to mitigate the effect of an attack while it is raging on. We present a novel technique that can effectively filter out the majority of DDoS Traffic, thus improving the overall throughput of the Legitimate Traffic. The proposed scheme leverages on and generalizes the IP traceback schemes to obtain the information concerning whether a network edge is on the attacking path of an attacker ("infected") or not ("clean"). We observe that while an attacker will have all the edges on its path marked as "infected", edges on the path of a Legitimate client will mostly be "clean". By preferentially filtering out packets that are inscribed with the marks of "infected" edges, the proposed scheme removes most of the DDoS Traffic while affecting Legitimate Traffic only slightly. Simulation results based on real-world network topologies (e.g., Skitter) all demonstrate that the proposed technique can improve the throughput of Legitimate Traffic by 3 to 7 times during DDoS attacks.
Jason R. Marden - One of the best experts on this subject based on the ideXlab platform.
-
ACC - Stackelberg Equilibria for Two-Player Network Routing Games on Parallel Networks
2020 American Control Conference (ACC), 2020Co-Authors: David Grimsman, Joao P. Hespanha, Jason R. MardenAbstract:We consider a two-player zero-sum network routing game in which a router wants to maximize the amount of Legitimate Traffic that flows from a given source node to a destination node and an attacker wants to block as much Legitimate Traffic as possible by flooding the network with malicious Traffic. We address scenarios with asymmetric information, in which the router must reveal its policy before the attacker decides how to distribute the malicious Traffic among the network links, which is naturally modeled by the notion of Stackelberg equilibria. The paper focuses on parallel networks, and includes three main contributions: we show that computing the optimal attack policy against a given routing policy is an NP-hard problem; we establish conditions under which the Stackelberg equilibria lead to no regret; and we provide a metric that can be used to quantify how uncertainty about the attacker's capabilities limits the router's performance.
Georgios S. Paschos - One of the best experts on this subject based on the ideXlab platform.
-
Sustainability of Service Provisioning Systems Under Stealth DoS Attacks
IEEE Transactions on Control of Network Systems, 2017Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We model a service provisioning system under attack by malicious intruders. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake requests attempting to degrade service provisioning—the fake Traffic is assumed low rate and, thus, it is practically undetectable. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed throughput region , that is, the Legitimate Traffic intensities that are guaranteed to be supported given specific intensities of the fake Traffic. The result is first obtained under the assumption that fake Traffic is routed using any static routing. Then, we relax this assumption allowing time-varying attacks. We show that depending on the resources of the malicious attacker and by the use of nonstationary attack policies, some of the servers are effectively neutralized and the guaranteed throughput is greatly compromised. We further examine the interaction between specific policies and encounter interesting phenomena, such as the Join-the-Shortest-Queue not being a maximally stable defense policy under specific time-varying attacks. The study offers defense insights, how to design the system, and how to balance the Traffic to sustain such attacks.
-
Sustainability of service provisioning systems under attack
ACM SIGMETRICS Performance Evaluation Review, 2013Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We propose a resource allocation model that captures the interaction between Legitimate users of a distributed service provisioning system with malicious intruders attempting to disrupt its operation. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake Traffic to the servers attempting to degrade service provisioning. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed region, i.e. the set of Legitimate Traffic intensities that are sustainable given specific intensities of the fake Traffic, under the assumption that the fake Traffic is routed using static policies. This assumption will be relaxed, allowing arbitrary routing policies, in the full version of this work
-
SIGMETRICS - Sustainability of service provisioning systems under attack
Proceedings of the ACM SIGMETRICS international conference on Measurement and modeling of computer systems - SIGMETRICS '13, 2013Co-Authors: Georgios S. Paschos, Leandros TassiulasAbstract:We propose a resource allocation model that captures the interaction between Legitimate users of a distributed service provisioning system with malicious intruders attempting to disrupt its operation. The system consists of a bank of servers providing service to incoming requests. Malicious intruders generate fake Traffic to the servers attempting to degrade service provisioning. Legitimate Traffic may be balanced using available mechanisms in order to mitigate the damage from the attack. We characterize the guaranteed region, i.e. the set of Legitimate Traffic intensities that are sustainable given specific intensities of the fake Traffic, under the assumption that the fake Traffic is routed using static policies. This assumption will be relaxed, allowing arbitrary routing policies, in the full version of this work.