Download presentation
Presentation is loading. Please wait.
Published byIrea Shelton Modified over 11 years ago
1
On the Necessity of Handling DDoS Traffic in the Middle of the Network Peter Reiher UCLA Computer Communications Workshop October 22, 2008
2
The DDoS Problem A target of DDoS is overwhelmed by packets What does that really mean? He gets more packets than he can handle But what is unable to handle those packets?
3
What Got Overwhelmed? The computer? The computers network interface? The LAN? The border router? An Internet router? Effective defenses must handle these attacks at or before the attacked resource
4
How Do We Handle DoS at Each Point? Any defense must be able to handle more traffic than the attack generates – Otherwise, the defense is itself overwhelmed Once one resource is overwhelmed, the impact continues downstream – You cant defend an attack that overwhelms your border router at your computer
5
The Implications 1.End point defenses cant help against attacks on upstream resources 2.End point defenses that cant handle a flood of a certain size require assistance – From better provisioned upstream defenses 3.Ultimately, some attacks cannot be handled without help in the middle of the network
6
What to Do About It? Nothing – Maybe the problem isnt that bad – Not quite nothing - manual solutions already used Improved manual solutions – Using what functionality? – Under whose control? Automated solutions – Using what functionality? – Under whose control?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.