Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Mayday: Distributed Filtering for Internet Services

Mayday is an architecture that combines overlay networks with lightweight packet filtering to defend against denial of service attacks. The overlay nodes perform client authentication and protocol verification, and then relay the requests to a protected server. The server is protected from outside attack by simple packet filtering rules that can be efficiently deployed even in backbone routers.

Mayday generalizes earlier work on Secure Overlay Services. Mayday improves upon this prior work by separating the overlay routing and the filtering, and providing a more powerful set of choices for each. Through this generalization, Mayday supports several different schemes that provide different balances of security and performance, continuum, and supports mechanisms that achieve better security or better performance than earlier systems. To evaluate both Mayday and previous work, we also present several practical attacks, two of them novel, that are effective against filtering-based systems.

David G. Andersen, Massachusetts Institute of Technology

BibTeX
@inproceedings {270404,
author = {David G. Andersen},
title = {Mayday: Distributed Filtering for Internet Services},
booktitle = {4th USENIX Symposium on Internet Technologies and Systems (USITS 03)},
year = {2003},
address = {Seattle, WA},
url = {https://www.usenix.org/conference/usits-03/mayday-distributed-filtering-internet-services},
publisher = {USENIX Association},
month = mar
}
Download

Links

Paper: 
http://www.usenix.org/events/usits03/tech/full_papers/andersen/andersen.pdf
Paper (HTML): 
http://www.usenix.org/events/usits03/tech/full_papers/andersen/andersen_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us