Florida International University
Edit Your Profile
FIU Discovery
Toggle navigation
Browse
Home
People
Organizations
Scholarly & Creative Works
Research Facilities
Support
Edit Your Profile
Shield: DoS filtering using traffic deflecting
Conference
Kline, E, Afanasyev, A, Reiher, P. (2011). Shield: DoS filtering using traffic deflecting .
37-42. 10.1109/ICNP.2011.6089077
Share this citation
Twitter
Email
Kline, E, Afanasyev, A, Reiher, P. (2011). Shield: DoS filtering using traffic deflecting .
37-42. 10.1109/ICNP.2011.6089077
Copy Citation
Share
Overview
Identifiers
Additional Document Info
View All
Overview
cited authors
Kline, E; Afanasyev, A; Reiher, P
authors
Afanasyev, Alexander
abstract
Denial-of-service (DoS) attacks continue to be a major problem on the Internet. While many defense mechanisms have been created, they all have significant deployment issues. This paper introduces a novel method that overcomes these issues, allowing a small number of deployed DoS defenses to act as secure on-demand shields for any node on the Internet. The proposed method is based on rerouting any packet addressed to a protected autonomous system (AS) through an intermediate filtering node - a shield. In this way, all potentially harmful traffic could be discarded before reaching the destination. The mechanisms for packet rerouting use existing routing techniques and do not require any kind of modification to the deployed protocols or routers. To make the proposed system feasible, from both deployment and usage points of view, traffic rerouting and outsourced filtering could be provided as an insurance-style on-demand service. © 2011 IEEE.
publication date
December 26, 2011
Identifiers
Digital Object Identifier (DOI)
https://doi.org/10.1109/icnp.2011.6089077
Additional Document Info
start page
37
end page
42