MULTOPS: A Data-Structure for Bandwidth Attack Detection.

SSYM'01 Proceedings of the 10th conference on USENIX Security Symposium - Volume 10(2001)

引用 269|浏览0
暂无评分
摘要
A denial-of-service bandwidth attack is an attempt to disrupt an online service by generating a traffic overload that clogs links or causes routers near the victim to crash. We propose a heuristic and a data-structure that network devices (such as routers) can use to detect (and eliminate) such attacks. With our method, each network device maintains a data-structure, MULTOPS, that monitors certain traffic characteristics. MULTOPS (MUlti-Level Tree for Online Packet Statistics) is a tree of nodes that contains packet rate statistics for subnet prefixes at different aggregation levels. The tree expands and contracts within a fixed memory budget. A network device using MULTOPS detects ongoing bandwidth attacks by the significant, disproportional difference between packet rates going to and coming from the victim or the attacker. MULTOPS-equipped routing software running on an off-the-shelf 700 Mhz Pentium III PC can process up to 340,000 packets per second.
更多
查看译文
关键词
network device,certain traffic characteristic,denial-of-service bandwidth attack,ongoing bandwidth attack,packet rate,packet rate statistic,traffic overload,MULTOPS-equipped routing software,MUlti-Level Tree,Mhz Pentium III PC,bandwidth attack detection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要