On The Insider: Oprah's Next Project on HBO
BNET Business Network:
BNET
TechRepublic
ZDNet

September 30th, 2009

Researchers devise way to deny denial-of-service attacks

Posted by Andrew Nusca @ 1:10 pm

Categories: Security

Tags: Denial Of Service, Researcher, Server, Distributed Denial Of Service, Computer, Filter Value, Security, Andrew Nusca

Researchers say they have devised a way to filter out denial of service attacks on computer networks, including cloud computing systems, improving security on government, commercial, and educational systems.

Methods do exist for configuring a network to filter out known denial of service (DoS) and distributed denial of service (DDoS) attack software and to recognize some of the traffic patterns associated with a mounting DoS attack.

But current filters usually rely on the computer being attacked to check the legitimacy of incoming information requests, consuming resources and, in the case of a massive DDoS, compounding the problem.

Computer engineers John Wu, Tong Liu, Andy Huang and David Irwin of Auburn University have developed a filter to protect systems against DoS attacks that they say circumvents this problem.

How? With the use of a new passive protocol that must be in place at each end of the connection, user and resource.

Their protocol, called “Identity-Based Privacy-Protected Access Control Filter,” or IPACF, is said to block threats to the gatekeeping Authentication Servers, allowing legitimate users with valid passwords to access private resources.

Here’s how it works:

The user’s computer has to present a filter value for the server to do a quick check. The filter value is a one-time secret that needs to be presented with the pseudo ID. The pseudo ID is also one-time use. Attackers cannot forge either of these values correctly and so attack packets are filtered out.

There is a drawback. The added layer of information transfer required for checking user requests could take up more resources needed by the server.

The researchers say they have tested how well the protocol manages a massive DDoS attack, simulating one on a network consisting of 1000 nodes with 10 Gbps bandwidth. The result? Little server degradation, negligible latency and minimal extra processor usage even when the 10 Gbps pipe to the authentication server is filled with DoS packets.

The protocol takes 6 nanoseconds to reject a non-legitimate information packet associated with the DoS attack, the researchers said.

Their results will be published in a forthcoming issue of international journal Information and Computer Security.

The protocol was first introduced at a conference in 2007.

Andrew NuscaAndrew J. Nusca is an associate editor for ZDNet and SmartPlanet. See his full profile and disclosure of his industry affiliations.

Email Andrew NuscaFollow on Twitter

  • Talkback
  • Most Recent of 6 Talkback(s)
RE: Researchers devise way to deny denial-of-service attacks
ZDNET Tech Update Today:
"Defense devised for DOS attacks"

"What do you think?" Me? I think that whoever writes the headlines for the ZDNet Tech Update Today needs to learn the difference between DOS (Disk Operating System) and DoS (Denial of Service). That's what I think.... (Read the rest)
Posted by: Barc777 Posted on: 10/01/09 You are currently: a Guest | | Terms of Use
How about a real-world test?  Eriamjh | 10/01/09
Why the server?  kd5auq | 10/01/09
Exactly.  Dr.C | 10/01/09
Great Idea, good Start  T Mike | 10/01/09
Wont work...  Ceridan | 10/01/09
RE: Researchers devise way to deny denial-of-service attacks  Barc777 | 10/01/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here