Back to Search Start Over

From Seek-and-Destroy to Split-and-Destroy: Connection Partitioning as an Effective Tool against Low-Rate DoS Attacks

Authors :
Vyron Kampourakis
Georgios Michail Makrakis
Constantinos Kolias
Source :
Future Internet, Vol 16, Iss 4, p 137 (2024)
Publication Year :
2024
Publisher :
MDPI AG, 2024.

Abstract

Low-rate Denial of Service (LDoS) attacks are today considered one of the biggest threats against modern data centers and industrial infrastructures. Unlike traditional Distributed Denial of Service (DDoS) attacks that are mainly volumetric, LDoS attacks exhibit a very small network footprint, and therefore can easily elude standard detection and defense mechanisms. This work introduces a defense strategy that may prove particularly effective against attacks that are based on long-lived connections, an inherent trait of LDoS attacks. Our approach is based on iteratively partitioning the active connections of a victim server across a number of replica servers, and then re-evaluating the health status of each replica instance. At its core, this approach relies on live migration and containerization technologies. The main advantage of the proposed approach is that it can discover and isolate malicious connections with virtually no information about the type and characteristics of the performed attack. Additionally, while the defense takes place, there is little to no indication of the fact to the attacker. We assess various rudimentary schemes to quantify the scalability of our approach. The results from the simulations indicate that it is possible to save the vast majority of the benign connections (80%) in less than 5 min.

Details

Language :
English
ISSN :
19995903
Volume :
16
Issue :
4
Database :
Directory of Open Access Journals
Journal :
Future Internet
Publication Type :
Academic Journal
Accession number :
edsdoj.4906c05b3f824da5950efe7b5a80f22b
Document Type :
article
Full Text :
https://doi.org/10.3390/fi16040137