作者
Wu-chi Feng, Edward Kaiser, Antoine Luu
发表日期
2005/3/13
研讨会论文
Proceedings IEEE 24th Annual Joint Conference of the IEEE Computer and Communications Societies.
卷号
4
页码范围
2372-2382
出版商
IEEE
简介
Client puzzles have been proposed in a number of protocols as a mechanism for mitigating the effects of distributed denial of service (DDoS) attacks. In order to provide protection against simultaneous attacks across a wide range of applications and protocols, however, such puzzles must be placed at a layer common to all of them; the network layer. Placing puzzles at the IP layer fundamentally changes the service paradigm of the Internet, allowing any device within the network to push load back onto those it is servicing. An advantage of network layer puzzles over previous puzzle mechanisms is that they can be applied to all traffic from malicious clients, making it possible to defend against arbitrary attacks as well as making previously voluntary mechanisms mandatory. In this paper, we outline goals which must be met for puzzles to be deployed effectively at the network layer. We then describe the design …
引用总数
200420052006200720082009201020112012201320142015201620172018201920202021202220232024176128871616112212104436423
学术搜索中的文章
W Feng, E Kaiser, A Luu - Proceedings IEEE 24th Annual Joint Conference of the …, 2005