Mitigating distributed denial of service attacks with Multiprotocol Label Switching--Traffic Engineering (MPLS-TE)

Download
Author
Vordos, Ioannis
Date
2009-03Advisor
Xie, Geoffrey
Second Reader
Fulp, John D.
Metadata
Show full item recordAbstract
A Denial of Service (DoS) occurs when legitimate users are prevented from using a service over a computer network. A Distributed Denial of Service (DDoS) attack is a more serious form of DoS in which an attacker uses the combined power of many hosts to flood and exhaust the networking or computing resources of a target server. In recent years, DDoS attacks have become a major threat to both civilian and military networks. Multi-Protocol Label Switching with Traffic Engineering (MPLS-TE) is an emerging technology that allows explicit, bandwidth-guaranteed packet forwarding paths to be established for different traffic flows. It provides a means for diverting packets of a suspected DDoS attack for analysis and cleaning before forwarding them to the actual destination. The objective of this research was to implement and evaluate the performance of an MPLS-TE based solution against DDoS attacks on a realistic test-bed network consisting of Cisco routers. The test-bed has been integrated with Snort®, an open source Intrusion Detection System (IDS), to achieve automatic detection and to mitigate DDoS attacks. The test-bed network was subject to a series of malicious traffic flows with varying degrees of intensity. The results demonstrated that MPLS-TE is very effective in mitigating such attacks. The overall system response time and the router CPU loads are comparable to those reported by two former NPS theses that examined alternative solutions based on BGP blackhole routing.
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Related items
Showing items related by title, author, creator and subject.
-
Toward an internet service provider (ISP) centric security
Price, Patrick D. (Monterey, California. Naval Postgraduate School, 2003-03);Individual users, businesses, and governments have become functionally dependent on the Internet's connectivity to interact at the most basic levels of social and economic intercourse. Yet self-propagating worms and ... -
A MODERN GREAT WALL: PRC SMART CITIES AND THE A2/AD IMPLICATIONS FOR AFSOC
Bowman, John D. (Monterey, CA; Naval Postgraduate School, 2022-06);The People’s Republic of China’s (PRC) proliferation of smart cities—integrated, government-controlled urban surveillance networks—has increased the persistent stare of surveillance technologies globally. While the place ... -
Session hijacking attacks in wireless local area networks
Onder, Hulusi (Monterey, California. Naval Postgraduate School, 2004-03);Wireless Local Area Network (WLAN) technologies are becoming widely used since they provide more flexibility and availability. Unfortunately, it is possible for WLANs to be implemented with security flaws which are not ...