Fine-grained capabilities for flooding DDoS defense using client reputations

  • Authors:
  • Maitreya Natu;Jelena Mirkovic

  • Affiliations:
  • University of Delaware, Newark, DE;University of Delaware, Newark, DE

  • Venue:
  • Proceedings of the 2007 workshop on Large scale attack defense
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Recently proposed capability mechanisms offer one part of the answer to the DDoS problem. They empower the victim to control the traffic it receives by selectively granting access to well-behaved clients via short-lived tickets. One major question still remains unanswered: how can victims distinguish between well-behaved and ill-behaved clients during the ticket-granting process. This paper offers one possible answer to this question, while also refining the basic capability mechanism. We propose the following novel features: (1) Reputation-based ticket-granting - long-term behavior of a client influences whether future tickets will be granted, (2) Fine-grained capabilities, which authorize access to the victim at a specified priority level based on a client's prior behavior, (3) Destination-based capabilities, granted by the defense located at the victim; this reduces operational cost, and breaks dependence of tickets on routes.