首页> 外文会议>IEEE Conference on Communications and Network Security >A moving target defense approach to mitigate DDoS attacks against proxy-based architectures
【24h】

A moving target defense approach to mitigate DDoS attacks against proxy-based architectures

机译:移动目标防御方法可缓解针对基于代理的体系结构的DDoS攻击

获取原文

摘要

Distributed Denial of Service attacks against high-profile targets have become more frequent in recent years. In response to such massive attacks, several architectures have adopted proxies to introduce layers of indirection between end users and target services and reduce the impact of a DDoS attack by migrating users to new proxies and shuffling clients across proxies so as to isolate malicious clients. However, the reactive nature of these solutions presents weaknesses that we leveraged to develop a new attack - the proxy harvesting attack - which enables malicious clients to collect information about a large number of proxies before launching a DDoS attack. We show that current solutions are vulnerable to this attack, and propose a moving target defense technique consisting in periodically and proactively replacing one or more proxies and remapping clients to proxies. Our primary goal is to disrupt the attacker's reconnaissance effort. Additionally, to mitigate ongoing attacks, we propose a new client-to-proxy assignment strategy to isolate compromised clients, thereby reducing the impact of attacks. We validate our approach both theoretically and through simulation, and show that the proposed solution can effectively limit the number of proxies an attacker can discover and isolate malicious clients.
机译:近年来,针对知名目标的分布式拒绝服务攻击变得更加频繁。为了应对这种大规模攻击,一些体系结构采用了代理,以在最终用户和目标服务之间引入间接层,并通过将用户迁移到新代理并在代理之间重新分配客户端来减少DDoS攻击的影响,从而隔离恶意客户端。但是,这些解决方案的反应性性质带来了我们可以利用来开发新攻击的弱点-代理收集攻击-它使恶意客户端可以在发起DDoS攻击之前收集有关大量代理的信息。我们展示了当前的解决方案容易受到这种攻击,并提出了一种移动目标防御技术,该技术包括定期主动地替换一个或多个代理并将客户端重新映射到代理。我们的主要目标是破坏攻击者的侦察工作。此外,为减轻持续的攻击,我们提出了一种新的客户端到代理分配策略,以隔离受感染的客户端,从而减少攻击的影响。我们在理论上和通过仿真验证了我们的方法,并表明所提出的解决方案可以有效地限制攻击者可以发现和隔离恶意客户端的代理数量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号