Controlling high bandwidth aggregates in the network

被引:237
作者
Mahajan, R
Bellovin, SM
Floyd, S
Ioannidis, J
Paxson, V
Shenker, S
机构
[1] ICIR, Berkeley, CA 94704 USA
[2] AT&T Labs Res, Florham Pk, NJ 07932 USA
关键词
D O I
10.1145/571697.571724
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The current Internet infrastructure has very few built-in protection mechanisms, and is therefore vulnerable to attacks and failures. In particular, recent events have illustrated the Internet's vulnerability to both denial of service (DoS) attacks and flash crowds in which one or more links in the network (or servers at the edge of the network) become severely congested. In both DoS attacks and flash crowds the congestion is due neither to a single flow, nor to a general increase in traffic, but to a well-defined subset of the traffic - an aggregate. This paper proposes mechanisms for detecting and controlling such high bandwidth aggregates. Our design involves both a local mechanism for detecting and controlling an aggregate at a single router, and a cooperative pushback mechanism in which a router can ask upstream routers to control an aggregate. While certainly not a panacea, these mechanisms could provide some needed relief from flash crowds and flooding-style DoS attacks. The presentation in this paper is a first step towards a more rigorous evaluation of these mechanisms.
引用
收藏
页码:62 / 73
页数:12
相关论文
共 24 条
[1]  
[Anonymous], 2001, ICMP TRACEBACK MESSA
[2]  
[Anonymous], 2000, IETF
[3]  
Borland J., 1999, NET VIDEO NOT YET RE
[4]  
Demers A., 1989, S P COMM ARCH PROT S
[5]   LINK-SHARING AND RESOURCE-MANAGEMENT MODELS FOR PACKET NETWORKS [J].
FLOYD, S ;
JACOBSON, V .
IEEE-ACM TRANSACTIONS ON NETWORKING, 1995, 3 (04) :365-386
[6]  
FLOYD S, 2001, PUSHBACK MESSAGES CO
[7]  
FLOYD S, 1998, ESTIMATING ARRIVAL R
[8]  
FLOYD S, 1999, IEEE ACM T NETWORKIN
[9]   Denial-of-service attacks rip the Internet [J].
Garber, L .
COMPUTER, 2000, 33 (04) :12-17
[10]  
GIBBENS RJ, 1999, AUTOMATICA INVITED P