The Experts below are selected from a list of 63 Experts worldwide ranked by ideXlab platform

Kihong Park - One of the best experts on this subject based on the ideXlab platform.

  • a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    European Journal of Operational Research, 2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution.

  • o r applications a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution. � 2005 Elsevier B.V. All rights reserved.

  • on the effectiveness of route based Packet filtering for distributed dos attack prevention in power law internets
    ACM Special Interest Group on Data Communication, 2001
    Co-Authors: Kihong Park
    Abstract:

    Denial of service (DoS) attack on the Internet has become a pressing problem. In this paper, we describe and evaluate route-based distributed Packet filtering (DPF), a novel approach to distributed DoS (DDoS) attack prevention. We show that DPF achieves proactiveness and scalability, and we show that there is an intimate relationship between the effectiveness of DPF at mitigating DDoS attack and power-law network topology.The salient features of this work are two-fold. First, we show that DPF is able to proactively filter out a significant fraction of Spoofed Packet flows and prevent attack Packets from reaching their targets in the first place. The IP flows that cannot be proactively curtailed are extremely sparse so that their origin can be localized---i.e., IP traceback---to within a small, constant number of candidate sites. We show that the two proactive and reactive performance effects can be achieved by implementing route-based filtering on less than 20% of Internet autonomous system (AS) sites. Second, we show that the two complementary performance measures are dependent on the properties of the underlying AS graph. In particular, we show that the power-law structure of Internet AS topology leads to connectivity properties which are crucial in facilitating the observed performance effects.

  • SIGCOMM - On the effectiveness of route-based Packet filtering for distributed DoS attack prevention in power-law internets
    ACM SIGCOMM Computer Communication Review, 2001
    Co-Authors: Kihong Park
    Abstract:

    Denial of service (DoS) attack on the Internet has become a pressing problem. In this paper, we describe and evaluate route-based distributed Packet filtering (DPF), a novel approach to distributed DoS (DDoS) attack prevention. We show that DPF achieves proactiveness and scalability, and we show that there is an intimate relationship between the effectiveness of DPF at mitigating DDoS attack and power-law network topology.The salient features of this work are two-fold. First, we show that DPF is able to proactively filter out a significant fraction of Spoofed Packet flows and prevent attack Packets from reaching their targets in the first place. The IP flows that cannot be proactively curtailed are extremely sparse so that their origin can be localized---i.e., IP traceback---to within a small, constant number of candidate sites. We show that the two proactive and reactive performance effects can be achieved by implementing route-based filtering on less than 20% of Internet autonomous system (AS) sites. Second, we show that the two complementary performance measures are dependent on the properties of the underlying AS graph. In particular, we show that the power-law structure of Internet AS topology leads to connectivity properties which are crucial in facilitating the observed performance effects.

Benjamin Armbruster - One of the best experts on this subject based on the ideXlab platform.

  • a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    European Journal of Operational Research, 2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution.

  • o r applications a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution. � 2005 Elsevier B.V. All rights reserved.

Cole J Smith - One of the best experts on this subject based on the ideXlab platform.

  • a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    European Journal of Operational Research, 2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution.

  • o r applications a Packet filter placement problem with application to defense against Spoofed denial of service attacks
    2007
    Co-Authors: Benjamin Armbruster, Cole J Smith, Kihong Park
    Abstract:

    We analyze a problem in computer network security, wherein Packet filters are deployed to defend a network against Spoofed denial of service attacks. Information on the Internet is transmitted by the exchange of IP Packets, which must declare their origin and destination addresses. A route-based Packet filter verifies whether the purported origin of a Packet is correct with respect to the current route map. We examine the optimization problem of finding a minimum cardinality set of nodes to filter in the network such that no Spoofed Packet can reach its destination. We prove that this problem is NP-hard, and derive properties that explicitly relate the filter placement problem to the vertex cover problem. We identify topologies and routing policies for which a polynomial-time solution to the minimum filter placement problem exists, and prove that under certain routing conditions a greedy heuristic for the filter placement problem yields an optimal solution. � 2005 Elsevier B.V. All rights reserved.

Peter Reiher - One of the best experts on this subject based on the ideXlab platform.

  • A Practical IP Spoofing Defense Through Route-Based Fltering
    2020
    Co-Authors: Jelena Mirkovic, Nikola Jevtic, Peter Reiher
    Abstract:

    We present the design and evaluation of the Clouseau system, which together with route-based filtering (RBF) acts as an effective and practical defense against IP spoofing. RBF’s performance critically depends on the completeness and the accuracy of the information used for Spoofed Packet detection. Clouseau autonomously harvests this information and updates it promptly upon a route change. RBF information is inferred by filters applying randomized drops to TCP data traffic, which arrives from suspicious or previously unknown sources, and observing subsequent retransmissions. No communication is required with Packet sources or other RBF routers, which makes Clouseau (and RBF) suitable for partial deployment. We show through experiments with a Clouseau prototype that the operation cost is reasonable and the legitimate TCP connections do not experience large delays because of randomized drops. The inference process is resilient to subversion by an attacker who is familiar with Clouseau. We motivate our work by showing that RBF brings instant benefit to the deploying network, and that it can drastically reduce the amount of Spoofed traffic in the Internet if deployed at as few as 50 chosen autonomous systems.

  • ACSAC - RESECT: Self-Learning Traffic Filters for IP Spoofing Defense
    Proceedings of the 33rd Annual Computer Security Applications Conference, 2017
    Co-Authors: Jelena Mirkovic, Erik Kline, Peter Reiher
    Abstract:

    IP spoofing has been a persistent Internet security threat for decades. While research solutions exist that can help an edge network detect Spoofed and reflected traffic, the sheer volume of such traffic requires handling further upstream. We propose RESECT---a self-learning Spoofed Packet filter that detects Spoofed traffic upstream from the victim by combining information about the traffic's expected route and about the sender's response to a few Packet drops. RESECT is unique in its ability to autonomously learn correct filtering rules when routes change, or when routing is asymmetric or multipath. Its operation has a minimal effect on legitimate traffic, while it quickly detects and drops Spoofed Packets. In isolated deployment, RESECT greatly reduces Spoofed traffic to the deploying network and its customers, to 8-26% of its intended rate. If deployed at 50 best-connected autonomous systems, RESECT protects the deploying networks and their customers from 99% of Spoofed traffic, and filters 91% of Spoofed traffic sent to any other destination. RESECT is thus both a practical and highly effective solution for IP spoofing defense.

Thomas Anderson - One of the best experts on this subject based on the ideXlab platform.

  • TVA: A DoS-Limiting Network Architecture
    IEEE ACM Transactions on Networking, 2008
    Co-Authors: Xiaowei Yang, David Wetherall, Thomas Anderson
    Abstract:

    We motivate the capability approach to network denial-of-service (DoS) attacks, and evaluate the traffic validation architecture (TVA) architecture which builds on capabilities. With our approach, rather than send Packets to any destination at any time, senders must first obtain ldquopermission to sendrdquo from the receiver, which provides the permission in the form of capabilities to those senders whose traffic it agrees to accept. The senders then include these capabilities in Packets. This enables verification points distributed around the network to check that traffic has been authorized by the receiver and the path in between, and hence to cleanly discard unauthorized traffic. To evaluate this approach, and to understand the detailed operation of capabilities, we developed a network architecture called TVA. TVA addresses a wide range of possible attacks against communication between pairs of hosts, including Spoofed Packet floods, network and host bottlenecks, and router state exhaustion. We use simulations to show the effectiveness of TVA at limiting DoS floods, and an implementation on Click router to evaluate the computational costs of TVA. We also discuss how to incrementally deploy TVA into practice.

  • a dos limiting network architecture
    ACM Special Interest Group on Data Communication, 2005
    Co-Authors: Xiaowei Yang, David Wetherall, Thomas Anderson
    Abstract:

    We present the design and evaluation of TVA, a network architecture that limits the impact of Denial of Service (DoS) floods from the outset. Our work builds on earlier work on capabilities in which senders obtain short-term authorizations from receivers that they stamp on their Packets. We address the full range of possible attacks against communication between pairs of hosts, including Spoofed Packet floods, network and host bottlenecks, and router state exhaustion. We use simulation to show that attack traffic can only degrade legitimate traffic to a limited extent, significantly outperforming previously proposed DoS solutions. We use a modified Linux kernel implementation to argue that our design can run on gigabit links using only inexpensive off-the-shelf hardware. Our design is also suitable for transition into practice, providing incremental benefit for incremental deployment.

  • SIGCOMM - A DoS-limiting network architecture
    Proceedings of the 2005 conference on Applications technologies architectures and protocols for computer communications - SIGCOMM '05, 2005
    Co-Authors: Xiaowei Yang, David Wetherall, Thomas Anderson
    Abstract:

    We present the design and evaluation of TVA, a network architecture that limits the impact of Denial of Service (DoS) floods from the outset. Our work builds on earlier work on capabilities in which senders obtain short-term authorizations from receivers that they stamp on their Packets. We address the full range of possible attacks against communication between pairs of hosts, including Spoofed Packet floods, network and host bottlenecks, and router state exhaustion. We use simulation to show that attack traffic can only degrade legitimate traffic to a limited extent, significantly outperforming previously proposed DoS solutions. We use a modified Linux kernel implementation to argue that our design can run on gigabit links using only inexpensive off-the-shelf hardware. Our design is also suitable for transition into practice, providing incremental benefit for incremental deployment.