Loading…
Attending this event?
Friday September 20, 2024 4:00pm - 4:31pm EDT

Link to paper

Abstract:
The focus of this paper is on an economics-based analysis and redesign of mitigation of volumetric Denial-of-Service (DDos) attacks utilizing the initial packets in connection-oriented protocols. These attacks have been documented for decades and their volume and impact have been growing enormously. The contributions of the paper are: (1) a novel evaluation framework based on all of efficacy, threat, overhead, and damage as experienced by applications; (2) a comparison of TCP with SYN Cookies and QUIC with Retries, the two accepted DDoS mitigation approaches in these two transport protocols; (3) evaluation of our alternative proposal to use SYN Proof-of-Work (SYN PoW) to address these volumetric attacks more effectively; and (4) an in-depth discussion of the economics of the various stakeholders in these scenarios. As demonstrated in this work, the SYN PoW type of approach not only moves much of the cost of mitigation onto the attackers, unlike current proposals, but also enables verification of validity of traffic to be handled anywhere in the network, rather than only at the end-points, giving network service providers an additional capability for reducing malicious traffic. A critical contribution is that this type of approach
Discussant
JW

Josephine Wolff

Tuft University
Authors
Friday September 20, 2024 4:00pm - 4:31pm EDT
Room YT17 WCL, 4300 Nebraska Ave, Washington, DC

Attendees (5)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link