Preventing the Flood: Incentive-Based Collaborative Mitigation for DRDoS Attacks

Anat Bremler-Barr, Matan Sabag

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Distributed denial of service (DDoS) attacks, especially distributed reflection denial of service attacks (DRDoS), have increased dramatically in frequency and volume in recent years. Such attacks are possible due to the attacker's ability to spoof the source address of IP packets. Since the early days of the internet, authenticating the IP source address has remained unresolved in the real world. Although there are many methods available to eliminate source spoofing, they are not widely used, primarily due to a lack of economic incentives. We propose a collaborative on-demand route-based defense technique (CORB) to offer efficient DDoS mitigation as a paid-for-service, and efficiently assuage reflector attacks before they reach the reflectors and flood the victim. The technique uses scrubbing facilities located across the internet at internet service providers (ISPs) and internet exchange points (IXPs). By transmitting a small amount of data based on border gateway protocol (BGP) information from the victim to the scrubbing facilities, we can filter out the attack without any false-positive cases. For example, the data can be sent using DOTS, a new signaling DDoS protocol that was standardized by the IETF. CORB filters the attack before it is amplified by the reflector, thereby reducing the overall cost of the attack. This provides a win-win financial situation for the victim and the scrubbing facilities that provide the service. We demonstrate the value of CORB by simulating a Memcached DRDoS attack using real-life data. Our evaluation found that deploying CORB on scrubbing facilities at approximately 40 autonomous systems blocks 90% of the attack and can reduce the mitigation cost by 85%.

Original languageEnglish
Title of host publication2022 IFIP Networking Conference, IFIP Networking 2022
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9783903176485
DOIs
StatePublished - 2022
Externally publishedYes
Event2022 IFIP Networking Conference, IFIP Networking 2022 - Catania, Italy
Duration: 13 Jun 202216 Jun 2022

Publication series

Name2022 IFIP Networking Conference, IFIP Networking 2022

Conference

Conference2022 IFIP Networking Conference, IFIP Networking 2022
Country/TerritoryItaly
CityCatania
Period13/06/2216/06/22

All Science Journal Classification (ASJC) codes

  • Artificial Intelligence
  • Hardware and Architecture
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Preventing the Flood: Incentive-Based Collaborative Mitigation for DRDoS Attacks'. Together they form a unique fingerprint.

Cite this