Show simple item record

Stateful Anycast for DDoS Mitigation

dc.date.accessioned2007-06-22T12:41:46Z
dc.date.accessioned2018-11-24T10:25:37Z
dc.date.available2007-06-22T12:41:46Z
dc.date.available2018-11-24T10:25:37Z
dc.date.issued2007-06-21
dc.identifier.urihttp://hdl.handle.net/1721.1/37601
dc.identifier.urihttp://repository.aust.edu.ng/xmlui/handle/1721.1/37601
dc.descriptionMEng thesis
dc.description.abstractDistributed denial-of-service (DDoS) attacks can easily cripple victim hosts or networks, yet effective defenses remain elusive. Normal anycast can be used to force the diffusion of attack traffic over a group of several hosts to increase the difficulty of saturating resources at or near any one of the hosts. However, because a packet sent to the anycast group may be delivered to any member, anycast does not support protocols that require a group member to maintain state (such as TCP). This makes anycast impractical for most applications of interest.This document describes the design of Stateful Anycast, a conceptual anycast-like network service based on IP anycast. Stateful Anycast is designed to support stateful sessions without losing anycast s ability to defend against DDoS attacks. Stateful Anycast employs a set of anycasted proxies to direct packets to the proper stateholder. These proxies provide DDoS protection by dropping a session s packets upon group member request. Stateful Anycast is incrementally deployable and can scale to support many groups.
dc.format.extent103 p.
dc.titleStateful Anycast for DDoS Mitigation


Files in this item

FilesSizeFormatView
MIT-CSAIL-TR-2007-035.pdf688.4Kbapplication/pdfView/Open
MIT-CSAIL-TR-2007-035.ps4.550Mbapplication/postscriptView/Open

This item appears in the following Collection(s)

Show simple item record