usenix conference policies
You are here
Active Internet Traffic Filtering: Real-Time Response to Denial-of-Service Attacks
This paper describes Active Internet Traffic Filtering (AITF), a mechanism for blocking highly distributed denial-of-service (DDoS) attacks. These attacks are an acute contemporary problem, with few practical solutions available today; we describe in this paper the reasons why no effective DDoS filtering mechanism has been deployed yet. We show that the current Internet's routers have sufficient filtering resources to thwart such attacks, with the condition that attack traffic be blocked close to its sources; AITF leverages this observation. Our results demonstrate that AITF can block a million-flow attack within seconds, while it requires only tens of thousands of wire-speed filters per participating router—an amount easily accommodated by today's routers. AITF can be deployed incrementally and yields benefits even to the very first adopters.
author = {Katerina Argyraki and David R. Cheriton},
title = {Active Internet Traffic Filtering: {Real-Time} Response to {Denial-of-Service} Attacks},
booktitle = {2005 USENIX Annual Technical Conference (USENIX ATC 05)},
year = {2005},
address = {Anaheim, CA},
url = {https://www.usenix.org/conference/2005-usenix-annual-technical-conference/active-internet-traffic-filtering-real-time},
publisher = {USENIX Association},
month = apr
}
connect with us