Power to the people: securing the internet one edge at a time

  • Authors:
  • Soon Hin Khor;Nicolas Christin;Tina Wong;Akihiro Nakao

  • Affiliations:
  • Carnegie Mellon University, Kobe, Hyogo, Japan;Carnegie Mellon University, Kobe, Hyogo, Japan;Carnegie Mellon University, Pittsburgh, PA;University of Tokyo, Tokyo, Japan

  • Venue:
  • Proceedings of the 2007 workshop on Large scale attack defense
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Despite a plethora of research in the area, none of the mechanisms proposed so far for Denial-of-Service (DoS) mitigation has been widely deployed. We argue in this paper that these deployment difficulties are primarily due to economic inefficiency, rather than to technical shortcomings of the proposed DoS-resilient technologies. We identify economic phenomena, negative externality---the benefit derived from adopting a technology depends on the action of others---and economic incentive misalignment---the party who suffers from an economic loss is different from the party who is in the best position to prevent that loss---as the main stumbling blocks of adoption. Our main contribution is a novel DoS mitigation architecture, Burrows, with an economic incentive realignment property. Burrows is obtained by re-factoring existing key DoS mitigation technologies, and can increase the "social welfare," i.e., economic benefit, of the entire Internet community---both infrastructure providers and the Internet users. At the core of Burrows is a wide-area virtual private network, or secure overlay, carved out of the existing Internet. Entry points into the Burrows overlay are controlled by gateways, which in addition to providing connectivity, minimize negative externality flowing between Burrows and the Internet. To rectify the aforementioned economic incentive misalignment, the power to realize Burrows is put into the hands of the Internet users. In addition, Burrows supports incremental deployment: even with as few as two participants, Burrows provides an environment more secure than without it.