Luận Án Tiến Sĩ: Phương Pháp Phòng Chống Tấn Công Tràn Băng Thông Internet Hiệu Quả

Luận án tiến sĩ phân tích scalable defense against internet bandwidth flooding attacks, xây dựng cơ sở lý luận, kiểm chứng thực nghiệm, đóng góp tri thức mới cho ngành.

Trường đại học

Stanford University

Chuyên ngành

Electrical Engineering

Người đăng

Ẩn danh

Thể loại

dissertation

2006

119
3
0

Phí lưu trữ

35 Point

Tóm tắt

I. Phòng chống tấn công mạng

Phòng chống tấn công mạng là một trong những vấn đề cấp bách trong bảo mật internet hiện nay. Các cuộc tấn công tràn băng thông, đặc biệt là tấn công DDoS, đã trở thành mối đe dọa nghiêm trọng đối với các hệ thống mạng. Các giải pháp hiện tại thường yêu cầu sự can thiệp thủ công từ nhà cung cấp dịch vụ internet (ISP), điều này không chỉ tốn kém mà còn kém hiệu quả khi các cuộc tấn công ngày càng tinh vi. Active Internet Traffic Filtering (AITF) được đề xuất như một cơ chế bảo vệ ở tầng IP, giúp tự động hóa quá trình chống lại các cuộc tấn công tràn băng thông.

1.1. Tấn công tràn băng thông

Tấn công tràn băng thông là một dạng tấn công DDoS, trong đó một lượng lớn lưu lượng không mong muốn được gửi đến nạn nhân nhằm làm cạn kiệt băng thông của họ. Các cuộc tấn công này thường khó phát hiện và ngăn chặn do tính chất phân tán và quy mô lớn. AITF giải quyết vấn đề này bằng cách xác định và chặn lưu lượng tấn công ngay tại các router gần nguồn tấn công, giảm thiểu tác động đến nạn nhân.

1.2. Giải pháp chống tấn công DDoS

Giải pháp chống tấn công DDoS hiệu quả cần đảm bảo khả năng mở rộng và dễ triển khai. AITF đáp ứng yêu cầu này bằng cách cho phép các ISP hợp tác để chặn lưu lượng tấn công mà không cần thiết lập các mối quan hệ đặc biệt giữa các ISP. Cơ chế này cũng tạo động lực cho các mạng hợp tác bằng cách đe dọa cắt quyền truy cập đến nạn nhân nếu không tuân thủ.

II. Bảo mật internet hiệu quả

Bảo mật internet hiệu quả đòi hỏi các giải pháp không chỉ ngăn chặn tấn công mà còn đảm bảo tính khả dụng của hệ thống. AITF đã chứng minh khả năng bảo vệ băng thông của nạn nhân trong các cuộc tấn công tràn băng thông, đồng thời giữ chi phí triển khai ở mức hợp lý. Cơ chế này có thể được triển khai dần dần trên internet mà không cần thay đổi cấu trúc mạng hiện có.

2.1. Phương pháp bảo vệ mạng

Phương pháp bảo vệ mạng của AITF tập trung vào việc xác định và chặn lưu lượng tấn công tại các router gần nguồn. Điều này giúp giảm tải cho nạn nhân và tăng hiệu quả của cơ chế bảo vệ. Các router này được yêu cầu chặn lưu lượng tấn công từ các nguồn trong mạng của họ, tạo ra một hệ thống phòng thủ phân tán và hiệu quả.

2.2. Hiệu quả bảo mật internet

Hiệu quả bảo mật internet của AITF được đánh giá thông qua khả năng duy trì băng thông cho nạn nhân trong các cuộc tấn công tràn băng thông. Các thử nghiệm cho thấy AITF có thể bảo vệ một tỷ lệ đáng kể băng thông của nạn nhân, đồng thời giữ chi phí triển khai ở mức thấp. Điều này làm cho AITF trở thành một giải pháp khả thi và hiệu quả trong thực tế.

III. Cách ngăn chặn tấn công mạng

Cách ngăn chặn tấn công mạng hiệu quả cần kết hợp giữa công nghệ và chiến lược quản lý. AITF cung cấp một cơ chế tự động để xác định và chặn lưu lượng tấn công, giảm thiểu sự phụ thuộc vào can thiệp thủ công. Cơ chế này cũng tạo ra động lực cho các mạng hợp tác bằng cách đe dọa cắt quyền truy cập đến nạn nhân nếu không tuân thủ.

3.1. Tấn công mạng và phòng chống

Tấn công mạng và phòng chống là một cuộc đua không ngừng giữa kẻ tấn công và người bảo vệ. AITF đại diện cho một bước tiến trong cuộc đua này bằng cách cung cấp một cơ chế bảo vệ hiệu quả và dễ triển khai. Cơ chế này không chỉ giúp ngăn chặn các cuộc tấn công hiện tại mà còn tạo ra một hệ thống phòng thủ linh hoạt cho các cuộc tấn công trong tương lai.

3.2. Tấn công băng thông rộng

Tấn công băng thông rộng là một trong những hình thức tấn công DDoS phổ biến nhất. AITF giải quyết vấn đề này bằng cách chặn lưu lượng tấn công ngay tại các router gần nguồn, giảm thiểu tác động đến nạn nhân. Cơ chế này cũng tạo ra động lực cho các mạng hợp tác bằng cách đe dọa cắt quyền truy cập đến nạn nhân nếu không tuân thủ.

21/02/2025
Luận án tiến sĩ scalable defense against internet bandwidth flooding attacks

Trích đoạn nội dung tài liệu

SCALABLE DEFENSE AGAINST INTERNET BANDWIDTH FLOODING ATTACKS A DISSERTATION SUBMITTED TO THE DEPARTMENT OF ELECTRICAL ENGINEERING AND THE COMMITTEE ON GRADUATE STUDIES OF STANFORD UNIVERSITY IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY Aikaterini Argyraki December 2006 UMI Number: 3242516 INFORMATION TO USERS The quality of this reproduction is dependent upon the quality of the copy submitted. Broken or indistinct print, colored or poor quality illustrations and photographs, print bleed-through, substandard margins, and improper alignment can adversely affect reproduction. In the unlikely event that the author did not send a complete manuscript and there are missing pages, these will be noted. Also, if unauthorized copyright material had to be removed, a note will indicate the deletion.

® UMI UMI Microform 3242516 Copyright 2007 by ProQuest Information and Learning Company. All rights reserved. This microform edition is protected against unauthorized copying under Title 17, United States Code. ProQuest Information and Learning Company 300 North Zeeb Road P.

Box 1346 Ann Arbor, MI 48106-1346 @ Copyright by Aikaterini Argyraki 2007 All Rights Reserved ii I certify that Ihave read this dissertation and that, in my opinion, it is fully adequate in scope and quality as a dissertation foz-Re degree of Doctor of Philosophy. Cheriton) Principal Adviser I certify that I have read this dissertation and that, in my opinion, it is fully adequate in scope and quality as a dissertation for the degree of r of Philosophy. X LÍ JÀ AN + NC (Nick McKeown) I certify that Ihave read this dissertation and that, in my opinion, it is fully adequate in scope and quality as a dissertation for the degree of Doctor of Philosophy. Ea (Nick Bambos) Approved for the University Committee on Graduate Studies.

ili Abstract During a distributed bandwidth-flooding attack, a large number of attack sources coordinate to send a high volume of undesired traffic to the intended victim; the goal is to exhaust the victim’s band- width, so that the victim fails to respond to its legitimate traffic. These attacks have proved difficult (sometimes impossible) to combat, as they require that action be taken before the victim’s tail cir- cuit. Current practice is typically restricted to the administrator of the victim calling their ISP and asking them to manually install filters to block the attack, an approach increasingly insufficient as attacks become more sophisticated. The intuitive response is to automate this process, i., enable the victim to automatically compute undesired-traffic signatures and send appropriate filtering re- quests to its ISP.

Yet, this approach faces significant challenges: Given the magnitude of currently witnessed attacks, it is unlikely that an ISP alone has enough resources to protect multiple attacked clients. Moreover, asking for help from other ISPs is complicated, in that it requires special inter-ISP relationships that do not exist today and raises security issues. This dissertation presents Active Internet Traffic Filtering (AITF), an IP-layer defense mech- anism against distributed bandwidth-flooding attacks that addresses these challenges. Three key points guide the design of the presented solution: First, an “attack source” is defined as an entity that has been asked to stop sending certain traffic and has been caught disobeying; this definition simplifies the task of the network (no need to detect complex attack patterns) and prevents false positives (innocent hosts prove their innocence by obeying).

Second, attack traffic is blocked at routers located close to the attack sources; this is key for the mechanism’s scalability, as each net- work that hosts attack sources becomes responsible for blocking its own misbehaving clients. Third, a network that hosts attack sources either cooperates and helps block attack traffic, or risks losing its access to the victim; this is a strong incentive to cooperate, especially if the victim is a popular public-access site — as is often the case with flooding-attack victims. We show that Active Internet Traffic Filtering preserves a significant percentage of a victim’s bandwidth in the face of bandwidth flooding, while the per-client cost for each participating ISP is already affordable by today’s ISPs and not expected to increase as the Internet grows. We also show that AITF can be incrementally deployed in the Internet without any special inter-ISP relationships.

We conclude that the IP-layer of the Internet can provide an effective, scalable and deployable solution against distributed bandwidth-flooding attacks. Acknowledgments First, I want to thank my adviser, David R. Painfully honest and politically incorrect, DRC is not your typical PhD adviser. He is tough and uncompromising, in an ongoing mission to reveal the one and only truth, or “the way God intended us” to build the Internet.

I am grateful to have shared his mission for the last six years. Working with him was a bumpy, never boring, always rewarding ride: he taught me to (i) search for the e = me? answer to every problem, (ii) use Occam’s razor, and (iii) respect (but not yield to) the power of the hack —~ because, as all DSGers know, great things in life come in groups of three. I also want to thank the two other members of my thesis committee, Professors Nick Bambos and Nick McKeown, for having the patience to read this dissertation and provide constructive feedback. I am grateful to all those who honored me with their cooperation and/or friendship during my graduate studies: Professor Scott Shenker became my mentor during my internship at the Interna- tional Computer Science Institute and has generously offered his ideas and advice ever since.

Petros Maniatis patiently taught me how to work with others and became my link to the research commu- nity as well as a great friend. Athina Markopoulou and George Candea were the closest witnesses to my PhD journey; Athina took me under her wing when I first started; George taught me that research can be at the same time serious and fun; they both provided inspiration, comfort when things got rough, and a round-the-clock emergency service. Daniel Braga de Faria, my office mate for five years, bravely responded to untimely calls for research/philosophical discussions; together with Evan Greenberg, Dapeng Zhu, Mark Gritter (thank you for patiently answering questions like “why is it again that we don’t like virtual circuits?”), Vince Laviano (DSG meetings, not to mention post-meeting therapy, were never the same without you), Sam Liang and Tassos Argyros, they all helped make the ride smoother and more rewarding. Ken Duda, chief superintendent of all things that matter at Arastra, showed great understanding when I took time off to finish this dissertation.

vi Finally, I am grateful to my dearest friends Tania Yendiki and Dimitris Makris, who lent me a bit of their strength and determination whenever I lost faith in myself. And to my parents, Sophocles and Soteria, and my brother George, who stood faithfully in my corner, waiting to console me, put me back on my feet, and send me out to fight the next round; this dissertation is for them. vil Contents Abstract iv Acknowledgments vi 1 Introduction 1.1 Denial of Service and Bandwidth Flooding.2 Identifying Undesired Traffic 1. LH HQ kẻ n®+aD l3 Filtering Undesired Traffic 2.

QC Q Q Q Q Q Q Q n n nu và ky sa 1.ee 2 Related Work \o 2. uc ch ng kg ky g 2. ng gà hà gi gi ga kia 2.4 Hardware-friendly LSRR Implementations .2 Undesired-traffic IdentiicaHon. cuc ch ra vi yt 2.3 Undesired-traffic Filtering.

ch Quà kia kia va 2.1 Overlay-based Proactive Filtering. kg ky kia gia 2. Black-listing and PointsofControl.4 White-listing and Network Capabilities. Vili 3 Basic Protocol and Properties 21 3.

cu kg kg va 22 3.2 Undesired-traffic Identification. Path-based Wire-speed Filtering ©.5 Provider-client Message Authentication .16 Non-compromised Path. ng kg k kh kg ki v v k va 26 Z2. Q0kg ki ko 26 c6“1 xa.

ae ẽẽ Ma .5 Resource-consumption ContfoÏ. c c c ch HQ HH sa 29 3.3 Properties SH HA.1 Maximum Number ofBlockedFlows. ng Q kg kg kg vâng 34 3. Legitimate and Deaf SOUTC€S.

Q Q Q Q Q Q Q Q n n Q n k k kg gà kg kg kg va 39 3.5 Non-coordinated On-off Sources.6 Coordinated On-off Sources 2. Q Q Q Q Q Q Q cu va 42 343/7 AITFILImIS.4 Summary äẵẳỗĂIÏT.Ha 45 4 Resource Requirements and Scalability 46 4.1 Satisfying Outbound Filtering Requests 2.1 Wire-speed Filters per Client.2 Reduced Filtering Capacity.2 Satisfying Inbound Filtering Requests 2.1 Wire-speed Filters per Cooperating Clhent.2 DRAM per Cooperating Client.3 Resources per Non-cooperating Client. uc cu ng gà k k k k cv k ki ki ki Kia 51 ix 4.4 Evolution of Resource Requirements and Cost. 5 Operation in Untrusted Environments 56 5.1 Malicious Filtering Requests.1 Verifying Filtering-request Orlgin .2 Verifying Non-cooperation Claims.2 Non-cooperating Source Gateways cuc uc Q cu ee KT k kia 61 5.1 Classifying a Source Gateway as Non-cooperating .2 Long-term Aggregate Filtering and Escalaion.

Impact of Non-cooperating Gateways on the Receiver’s Tail Circuit .4 Maximum Number of Flows Blocked with Long-term Filters.3 Spoofed Addresses and Paths.1 Source-address Spoolng. ch ha va 66 5. cv k k kg kg xa va 67 5. ———— ee 71 6 Evaluation through Simulation 74 6.

cu ng gà ga kg và 74 6.2 Identification and Request Overhead. cu nu ca 76 6.3 Tail-circuit Capacity Loss: Non-coordinated Sources.4 Tail-circuit Capacity Loss: Coordinated Sources. 88 7 Conclusions 89 7A Summary =ốẮẽ 89 7.2 Future Work 0ee 91 7. gà kg kg ki kg kg k k k Na 92 A_ AITF Message Format 94 Bibliography 95 List of Tables 3.1 The parameters of the AITF protocol.

The example values are justified later in this chapter (when we discuss AITF properties) and in Chapter 4 (when we discuss AITF cost).2 Qualitative description of the receiver J's states. F’ is the undesired flow.3 State machine for the receiver R. The first column lists all states; the second column de- scribes the events that trigger a set of actions in each state; the third column describes in pseudo-code the actions that take place as a result of each event, including state transitions; the fourth column repeats the state to which we transition after these actions. F is the undesired flow and ?¿„ is the receiver’s gateway, Wy is the filtering window, defined in Table 3.4 Qualitative description of the receiver’s gateway (su) states.

F is the undesired flow; REQout is a parameter definedinTable3.5 State machine for the receiver’s gateway R,. The first column lists all states, the second column describes the events that trigger a set of actions in each state; the third column describes in pseudo-code the actions that take place as a result of each event, including state transitions; the fourth column repeats the state to which we transition after these actions. R is the undesired-traffic receiver, F is the undesired flow, and S,,, is the source gateway; REQoue and Tg, are AITF parameters defined in Table3.6 Qualitative description of the source gateway (S,,,) states. #' is the undesired flow, REQin, W; and Tg, are AITF parameters defined in Table3.

6 eee ee es 32 3.7 State machine for the source gateway Ss„. The first column lists all non-terminal states, the second column describes the events that trigger a set of actions in each state; the third column describes in pseudo-code the actions that take place as a result of each event, includ- ing state transitions; the fourth column repeats the state to which we transition after these actions, F is the undesired flow and S is the undesired-flow source. W;, REQ:, and Tas are parameters defined In Table3. Q2 nu nu kg va 33 Xi 3.8 Characteristics of the receiver and the undesired traffic that we use to quantify the effective- nessOfAITF 2.1 Qualitative description of the receiver (f)’s states with respect to a flow F.

Ty, is an AITF parameter defined in Table3.2 State machine for the receiver R.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ