Defending Root DNS Servers against DDoS Using Layered Defenses (Extended)

被引:1
|
作者
Rizvi, A. S. M. [1 ]
Mirkovic, Jelena [1 ]
Heidemann, John [1 ]
Hardaker, Wesley [1 ]
Story, Robert [1 ]
机构
[1] Univ Southern Calif, Informat Sci Inst, Los Angeles, CA 90007 USA
基金
美国国家科学基金会;
关键词
DDoS; DNS; Filtering; ATTACKS;
D O I
10.1016/j.adhoc.2023.103259
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks exhaust resources, leaving a server unavailable to legitimate clients. The Domain Name System (DNS) is a frequent target of DDoS attacks. Since DNS is a critical infrastructure service, protecting it from DoS is imperative. Many prior approaches have focused on specific filters or anti-spoofing techniques to protect generic services. DNS root nameservers are more challenging to protect, since they use fixed IP addresses, serve very diverse clients and requests, receive predominantly UDP traffic that can be spoofed, and must guarantee high quality of service. In this paper we propose a layered DDoS defense for DNS root nameservers. Our defense uses a library of defensive filters, which can be optimized for different attack types, with different levels of selectivity. We further propose a method that automatically and continuously evaluates and selects the best combination of filters throughout the attack. We show that this layered defense approach provides exceptional protection against all attack types using traces of ten real attacks from a DNS root nameserver. Our automated system can select the best defense within seconds and quickly reduces traffic to the server within a manageable range, while keeping collateral damage lower than 2%. We show our system can successfully mitigate resource exhaustion using replay of a real-world attack. We can handle millions of filtering rules without noticeable operational overhead.
引用
收藏
页数:12
相关论文
共 14 条
  • [1] Defending Root DNS Servers Against DDoS Using Layered Defenses
    Rizvi, A. S. M.
    Mirkovic, Jelena
    Heidemann, John
    Hardaker, Wesley
    Story, Robert
    2023 15TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS, COMSNETS, 2023,
  • [2] Using Cloud Computing MapReduce operations to Detect DDoS Attacks on DNS servers
    Trejo, Luis A.
    Alonso, Roberto
    Avila, Adrian
    Monroy, Raul
    Sanchez, Erika
    Vazquez, Jorge
    Maqueo, Mario
    IBERGRID: 4TH IBERIAN GRID INFRASTRUCTURE CONFERENCE PROCEEDINGS, 2010, : 493 - 505
  • [3] A Cost Optimized Solution for Defending Against DDoS Attacks: An Analysis of a Multi-layered Architecture
    Gaylah K.D.
    Vaghela R.S.
    Zongo W.-B.S.
    SN Computer Science, 4 (5)
  • [4] Defending HTTP Web Servers against DDoS Attacks through Busy Period-based Attack Flow Detection
    Nam, Seung Yeob
    Djuraev, Sirojiddin
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2014, 8 (07): : 2512 - 2531
  • [5] Detection of DoS/DDoS attack against HTTP Servers using Naive Bayesian
    Katkar, Vijay
    Zinjade, Amol
    Dalvi, Suyed
    Bafna, Tejal
    Mahajan, Rashmi
    1ST INTERNATIONAL CONFERENCE ON COMPUTING COMMUNICATION CONTROL AND AUTOMATION ICCUBEA 2015, 2015, : 280 - 285
  • [6] Using SDN Approach to Secure Cloud Servers Against Flooding Based DDoS Attacks
    Guesmi, Houda
    Saidane, Leila Azouz
    2017 25TH INTERNATIONAL CONFERENCE ON SYSTEMS ENGINEERING (ICSENG), 2017, : 309 - 315
  • [7] Defending against DDoS Attacks under IP Spoofing Using Image Processing Approach
    Kim, Tae Hwan
    Kim, Dong Seong
    Jung, Hee Young
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2016, E99B (07) : 1511 - 1522
  • [8] Defending Against Evolving DDoS Attacks: A Case Study Using Link Flooding Incidents
    Kang, Min Suk
    Gligor, Virgil D.
    Sekar, Vyas
    SECURITY PROTOCOLS XXIV, 2017, 10368 : 47 - 57
  • [9] Defending Against Ddos Attacks in Rpl Using Subjective Logic Based Trust Approach For IOT
    Kiran, Vidhu
    Sardana, Anita
    Kaur, Puninder
    2022 2nd International Conference on Advance Computing and Innovative Technologies in Engineering, ICACITE 2022, 2022, : 1656 - 1660
  • [10] DNS-ADVP: A Machine Learning Anomaly Detection and Visual Platform to Protect Top-Level Domain Name Servers Against DDoS Attacks
    Trejo, Luis A.
    Ferman, Victor
    Angel Medina-Perez, Miguel
    Arredondo Giacinti, Fernando Miguel
    Monroy, Raul
    Ramirez-Marquez, Jose E.
    IEEE ACCESS, 2019, 7 : 116358 - 116369