论文标题

用光击打火:使用光学层防御DDOS攻击的案例

Fighting Fire with Light: A Case for Defending DDoS Attacks Using the Optical Layer

论文作者

Hall, Matthew, Durairajan, Ramakrishnan, Sekar, Vyas

论文摘要

DDOS攻击景观的增长速度是一个前所未有的速度。受到光学网络的最新进展的启发,我们在本文中为光学层吸引DDOS防御(O-LAD)提供了理由。我们的方法利用光学层通过使用路线对(备份)波长进行动态重新配置来迅速隔离攻击流量---桥接(a)DDOS攻击景观的演变和(b)光学层的创新之间的差距(例如,重新配置的光学设备)。我们表明,交通概况的物理分离允许对可疑流的细粒度处理,并在面对攻击时为良性流量提供更好的性能。我们提出了对合法流量的吞吐量和延伸攻击强度的合法流量的初步结果。我们还为安全,光学和系统社区确定了许多开放问题:建模多样化的DDOS攻击(例如固定速度与可变速率,可检测到可检测到的可检测到的),建立具有光学进步的完整防御系统(例如OpenConfig),以及用于防御范围,以防御范围,以防御范围,以防御较大的攻击范围(E. reconniss reconniss),reconniss reconnaiss,Network Network Networt。

The DDoS attack landscape is growing at an unprecedented pace. Inspired by the recent advances in optical networking, we make a case for optical layer-aware DDoS defense (O-LAD) in this paper. Our approach leverages the optical layer to isolate attack traffic rapidly via dynamic reconfiguration of (backup) wavelengths using ROADMs---bridging the gap between (a) evolution of the DDoS attack landscape and (b) innovations in the optical layer (e.g., reconfigurable optics). We show that the physical separation of traffic profiles allows finer-grained handling of suspicious flows and offers better performance for benign traffic in the face of an attack. We present preliminary results modeling throughput and latency for legitimate flows while scaling the strength of attacks. We also identify a number of open problems for the security, optical, and systems communities: modeling diverse DDoS attacks (e.g., fixed vs. variable rate, detectable vs. undetectable), building a full-fledged defense system with optical advancements (e.g., OpenConfig), and optical layer-aware defenses for a broader class of attacks (e.g., network reconnaissance).

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源