SwePub
Sök i LIBRIS databas

  Extended search

id:"swepub:oai:DiVA.org:ltu-81409"
 

Search: id:"swepub:oai:DiVA.org:ltu-81409" > Mitigating DRDoS Ne...

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Mitigating DRDoS Network Attacks via Consolidated Deny Filter Rules

Booth, Todd, 1959- (author)
Luleå tekniska universitet,Digitala tjänster och system
Andersson, Karl, 1970- (author)
Luleå tekniska universitet,Datavetenskap
 (creator_code:org_t)
Republic of Korea : Innovative Information Science & Technology Research Group (ISYOU), 2020
2020
English.
In: Research Briefs on Information & Communication Technology Evolution (ReBICTE). - Republic of Korea : Innovative Information Science & Technology Research Group (ISYOU). - 2383-9201. ; 6
  • Journal article (peer-reviewed)
Abstract Subject headings
Close  
  • This article is concerning distributed reflection denial of service (DRDoS) attacks.  These DRDoS attacks are more frequent and large scale, and are one of the biggest threats on the Internet. This paper discusses the best way to defend from these attacks using public cloud defenses, such as Amazon AWS, Google GCP, and Microsoft Azure, at a very low cost.  Our mitigation strategy takes advantage of the fact that the attacker does not have full control to change the source IP port to anything they want, when used in these reflective attacks.  We propose to have the customer host their Web servers and other types of supporting servers in the public cloud.  The cloud provider then reserves a /CIDR block of IP addresses, which will be protected.  The cloud providers customers who opt in, will be allocated an IP address from this block.  This block will be used as the source IP address deny portion of the firewall rule-sets.  Then the public cloud providers will use BGP4 Flow-Spec or some scripting solution, to have their IP service provider neighbors perform the actual filtering of the DRDoS attack traffic concerning attacks against these servers.

Subject headings

SAMHÄLLSVETENSKAP  -- Medie- och kommunikationsvetenskap -- Systemvetenskap, informationssystem och informatik med samhällsvetenskaplig inriktning (hsv//swe)
SOCIAL SCIENCES  -- Media and Communications -- Information Systems, Social aspects (hsv//eng)
NATURVETENSKAP  -- Data- och informationsvetenskap -- Datavetenskap (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Computer Sciences (hsv//eng)

Keyword

DDoS
DRDoS
BGP4 Flow-Spec
Cloud security
Information systems
Informationssystem
Pervasive Mobile Computing
Distribuerade datorsystem

Publication and Content Type

ref (subject category)
art (subject category)

Find in a library

To the university's database

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Search outside SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Close

Copy and save the link in order to return to this view