Papers

Peer-reviewed
Jun 18, 2014

Oblivious DDoS mitigation with locator/ID separation protocol

ACM International Conference Proceeding Series
  • Kazuya Okada
  • ,
  • Hiroaki Hazeyama
  • ,
  • Youki Kadobayashi

Volume
2014-
Number
May
First page
8:1-8:6
Last page
Language
English
Publishing type
Research paper (international conference proceedings)
DOI
10.1145/2619287.2619291
Publisher
Association for Computing Machinery

The need to keep an attacker oblivious of an attack mitigation effort is a very important component of a defense against denial of services (DoS) and distributed denial of services (DDoS) attacks because it helps to dissuade attackers from changing their attack patterns. Conceptually, DDoS mitigation can be achieved by two components. The first is a decoy server that provides a service function or receives attack traffic as a substitute for a legitimate server. The second is a decoy network that restricts attack traffic to the peripheries of a network, or which reroutes attack traffic to decoy servers. In this paper, we propose the use of a two-stage map table extension Locator/ID Separation Protocol (LISP) to realize a decoy network. We also describe and demonstrate how LISP can be used to implement an oblivious DDoS mitigation mechanism by adding a simple extension on the LISP MapServer. Together with decoy servers, this method can terminate DDoS traffic on the ingress end of an LISP-enabled network. We verified the effectiveness of our proposed mechanism through simulated DDoS attacks on a simple network topology. Our evaluation results indicate that the mechanism could be activated within a few seconds, and that the attack traffic can be terminated without incurring overhead on the MapServer.

Link information
DOI
https://doi.org/10.1145/2619287.2619291
DBLP
https://dblp.uni-trier.de/rec/conf/cfi/OkadaHK14
URL
http://doi.acm.org/10.1145/2619287.2619291
URL
http://dblp.uni-trier.de/db/conf/cfi/cfi2014.html#conf/cfi/OkadaHK14
ID information
  • DOI : 10.1145/2619287.2619291
  • DBLP ID : conf/cfi/OkadaHK14
  • SCOPUS ID : 84954532482

Export
BibTeX RIS