Tumbler: Adaptable Link Access in the Bots-Infested Internet

Yao Zhang,Xiaoyou Wang,Adrian Perrig,Zhiming Zheng
DOI: https://doi.org/10.1016/j.comnet.2016.06.005
IF: 5.493
2016-01-01
Computer Networks
Abstract:Despite large-scale flooding attacks, capability-based defense schemes provide end hosts with guaranteed communication. However, facing the challenges of enabling scalable bandwidth fair sharing and adapting to attack strategies, none of the existing schemes adequately stand. In this paper we present Tumbler, a flooding attack defense mechanism that provides scalable competition-based bandwidth fairness at the Autonomous System (AS) granularity, and on-demand bandwidth allocation for end hosts in each AS. Tumbler enforces adaptability in the capability establishment via competition factors that are calculated upon leaf ASes' bandwidth utilization and reputation. Transit ASes independently manage each competition factor based on the corresponding feedback from dedicated bandwidth accounting and monitoring policies. Through Internet-scale simulations, we demonstrate the effectiveness of Tumbler against a variety of attack scenarios and illustrate the deployment benefits for ISPs.
What problem does this paper attempt to address?