loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
DARPA Information Survivability Conference and Exposition - Volume I
NetBouncer: Client-legitimacy-based High-performance DDoS Filtering
Washington, DC
April 22-April 24
ISBN: 0-7695-1897-4
Roshan Thomas, Network Associates, Inc.
Brian Mark, George Mason University
Tommy Johnson, Network Associates, Inc.
James Croall, Network Associates, Inc.
We describe "NetBouncer", an approach and set of technologies for providing practical and high-performance defenses against distributed denial-of-service (DDoS) attacks. The central innovation in the NetBouncer approach to filtering and mitigating DDoS attacks is the ability to distinguish legitimate traffic from illegitimate ones so as to enable the discarding of only illegitimate traffic. In particular, this allows a NetBouncer-enabled network to distinguish DDoS congestion from flash crowd congestion situations. This provides a unique advantage over other DDoS mitigation techniques such as those based on filtering and congestion control where some loss of legitimate traffic is inevitable. The NetBouncer approach is characterized as an end-point-based solution to DDoS protection. It provides localized protection at potential choke points or bottlenecks that may exist in front of hosts and servers. NetBouncer attempts to block traffic as close to the victim as possible, while upstream of the nearest bottleneck. The immediate manifestation of NetBouncer technology is as a high-speed packet processing in-line appliance based on network processor technology. However, the long-term evolution, adoption and integration of NetBouncer technology may be in the back-plane/fast path of commercial high-speed routers.
Citation:
Roshan Thomas, Brian Mark, Tommy Johnson, James Croall, "NetBouncer: Client-legitimacy-based High-performance DDoS Filtering," discex, vol. 1, pp.14, DARPA Information Survivability Conference and Exposition - Volume I, 2003
Usage of this product signifies your acceptance of the Terms of Use.