论文标题
区分防御DDOS攻击;一种新颖的方法
Discriminating Defense Against DDoS Attacks; a Novel Approach
论文作者
论文摘要
Osterwile等人最近的一篇论文(大约2020年),题为“ 21年的分布式拒绝服务:行动呼吁”,说:“我们在反对分布式拒绝服务的战争中落后。除非我们现在采取行动,否则互联网的未来可能会受到威胁。”以及Peng等人的早期(大约2007年)论文。指出:“防御DDOS攻击的主要挑战是如何区分合法的服务请求与恶意访问尝试。”这一挑战尚未得到满足,这可以说是Osterwile等人描述的可怕情况的主要原因。 - 十三年后。本文试图通过启用一个站点来定义其认为重要的消息的类型,并通过在给定站点认为重要的信息以及发送给它的所有其他消息之间引入歧视标准,并试图满足这一挑战的近似值。本文介绍了基于此标准的两种抗DDOS机制。其中之一依赖路由器的轻量级支撑;另一个没有。
A recent paper (circa 2020) by Osterwile et al., entitled "21 Years of Distributed Denial of Service: A Call to Action", states: "We are falling behind in the war against distributed denial-of-service attacks. Unless we act now, the future of the Internet could be at stake." And an earlier (circa 2007) paper by Peng et al. states: "a key challenge for the defense [against DDoS attacks] is how to discriminate legitimate requests for service from malicious access attempts." This challenge has not been met yet, which is, arguably, a major reason for the dire situation described by Osterwile et al. -- thirteen years later. This paper attempts to meet an approximation to this challenge, by enabling a a site to define the kind of messages that it considers important, and by introducing an unambiguous criterion of discrimination between messages that a given site considers important, and all other messages sent to it. Two anti-DDoS mechanisms based on this criterion are introduced in this paper. One of these relies on lightweight support by routers; and the other one does not.