CICI: RSARC: DDoS Defense In Depth for DNS

CICI:RSARC:DNS 深度 DDoS 防御

基本信息

  • 批准号:
    1739034
  • 负责人:
  • 金额:
    $ 99.72万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2017
  • 资助国家:
    美国
  • 起止时间:
    2017-10-01 至 2021-09-30
  • 项目状态:
    已结题

项目摘要

Distributed Denial-of-Service (DDoS) attacks continue to plague the Internet. Attacks have significant effects on social media, content and many other Internet services. Malicious actors are becoming increasingly sophisticated and are employing methods to hide their attack origins, amplify the size of their attacks, and use huge botnets that simply overwhelm their targets. This project directly addresses these advanced attacks by developing and deploying a defense in depth approach, called Deep Layers, to mitigate the types of DDoS attacks seen most recently. Deep Layers will be deployed to protect B-Root, the critical infrastructure that is one of thirteen providers of the Domain Name System (DNS) service for the top level (root) of Internet names that begin with www.The Deep Layers solution to DDoS attacks integrates two approaches to filter spoofed traffic, two approaches to identify known-good traffic (hop-count filtering and prioritization of known-good clients), with the addition of a cloud-based scaling component to handle the largest attacks. The combination of these steps address an array of increasingly sophisticated attacks, ranging from those seen today to those that would be possible in the future, significantly increasing DNS resilience to DDoS attacks. The project integrates and extends several recent successful research approaches to DDoS defense and demonstrates their effectiveness on the B-root critical infrastructure. The project demonstrates Deep layers on the B-Root DNS server, and makes it available to other DNS operations as open source software. The work vastly improves the reliability of the DNS critical infrastructure, benefiting all Internet users.
分布式拒绝服务(DDOS)攻击继续困扰着互联网。攻击对社交媒体,内容和许多其他互联网服务有重大影响。恶意演员正在变得越来越复杂,并采用方法来隐藏其攻击起源,扩大其攻击的大小,并使用巨大的僵尸网络,使他们的目标不堪重负。该项目通过开发和部署一种称为深层的防御方法来直接解决这些高级攻击,以减轻最近看到的DDOS攻击类型。将部署深层以保护B-Root,这是域名系统(DNS)的13个提供商之一,用于互联网名称的顶级服务(DNS)服务,以www. www. www. www.ddos的深层解决方案。DDOS解决DDOS的解决方案DDOS攻击的两种方法可与已知的交通相结合,以确定已知的交通型号,并在交通型号中(预先设置过过滤器),并构成了过滤量的杂货,并构成了杂货的杂货。缩放组件以处理最大的攻击。这些步骤的结合解决了一系列越来越复杂的攻击,从今天看到的攻击到将来可能的攻击,大大提高了DNS对DDOS攻击的弹性。该项目整合并扩展了最近成功的DDOS防御研究方法,并证明了它们对B根临界基础设施的有效性。该项目在B-Root DNS服务器上演示了深层层,并将其作为开源软件提供给其他DNS操作。这项工作大大提高了DNS关键基础架构的可靠性,从而使所有互联网用户受益。

项目成果

期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
TsuNAME: exploiting misconfiguration and vulnerability to DDoS DNS
TsuNAME:利用 DDoS DNS 的错误配置和漏洞
  • DOI:
    10.1145/3487552.3487824
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Moura, Giovane C.;Castro, Sebastian;Heidemann, John;Hardaker, Wes
  • 通讯作者:
    Hardaker, Wes
Anycast In context: a tale of two systems
任播上下文:两个系统的故事
  • DOI:
    10.1145/3452296.3472891
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Koch, Thomas;Katz-Bassett, Ethan;Heidemann, John;Calder, Matt;Ardi, Calvin;Li, Ke
  • 通讯作者:
    Li, Ke
Cache Me If You Can: Effects of DNS Time-to-Live
如果可以的话缓存我:DNS 生存时间的影响
  • DOI:
    10.1145/3355369.3355568
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Moura, Giovane C.;Heidemann, John;Schmidt, Ricardo de;Hardaker, Wes
  • 通讯作者:
    Hardaker, Wes
When the Dike Breaks: Dissecting DNS Defenses During DDoS
当堤坝决堤时:剖析 DDoS 期间的 DNS 防御
  • DOI:
    10.1145/3278532.3278534
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Moura, Giovane C.;Heidemann, John;Müller, Moritz;de O. Schmidt, Ricardo;Davids, Marco
  • 通讯作者:
    Davids, Marco
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

John Heidemann其他文献

Auditing for Racial Discrimination in the Delivery of Education Ads
教育广告投放中的种族歧视审核
Detecting Malicious Activities with DNS Backscatter
使用 DNS 反向散射检测恶意活动
  • DOI:
    10.1145/2815675.2815706
  • 发表时间:
    2015
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Kensuke Fukuda;John Heidemann
  • 通讯作者:
    John Heidemann
Deep Dive into NTP Pool's Popularity and Mapping
深入探讨 NTP 池的流行度和映射
Privacy protection technologies: From protecting questioner to personal data anonymization
隐私保护技术:从保护提问者到个人数据匿名化
Anycast Polarization in the Wild
野外任播极化

John Heidemann的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('John Heidemann', 18)}}的其他基金

Collaborative Research: IMR:MM-1B: Privacy in Internet Measurements Applied To WAN and Telematics
合作研究:IMR:MM-1B:应用于广域网和远程信息处理的互联网测量隐私
  • 批准号:
    2319409
  • 财政年份:
    2023
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Continuing Grant
IMR: RI-P: Safe And Flexible Experimental Dataset Access and Sharing-Planning (SAFED-ASP)
IMR:RI-P:安全灵活的实验数据集访问和共享规划 (SAFED-ASP)
  • 批准号:
    2224467
  • 财政年份:
    2022
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
Collaborative Research: CNS Core: Medium: A Traffic Map for the Internet
合作研究:CNS 核心:媒介:互联网流量地图
  • 批准号:
    2212480
  • 财政年份:
    2022
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Continuing Grant
RAPID: Measuring the Internet during Novel Coronavirus to Evaluate Quarantine (RAPID-MINSEQ)
RAPID:测量新型冠状病毒期间的互联网以评估隔离情况 (RAPID-MINSEQ)
  • 批准号:
    2028279
  • 财政年份:
    2020
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CNS Core: Small: Event Identification in Evaluation of Internet Outages
CNS 核心:小型:互联网中断评估中的事件识别
  • 批准号:
    2007106
  • 财政年份:
    2020
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CCRI: Medium: DNS, Identity, and Internet Naming for Experimentation and Research (DIINER)
CCRI:媒介:用于实验和研究的 DNS、身份和互联网命名 (DINER)
  • 批准号:
    1925737
  • 财政年份:
    2019
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Continuing Grant
RAPID: Interactive Internet Outages Visualization to Assess Disaster Recovery
RAPID:用于评估灾难恢复的交互式互联网中断可视化
  • 批准号:
    1806785
  • 财政年份:
    2018
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CI-P: Planning for Identity and Naming Experimentation Shared Testbed
CI-P:规划身份和命名实验共享测试台
  • 批准号:
    1513213
  • 财政年份:
    2015
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
MRI: Development of an Always-Available Testbed for Underwater Networking Research
MRI:开发用于水下网络研究的始终可用的测试台
  • 批准号:
    0821750
  • 财政年份:
    2008
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
NeTS-NBD-SGER: Map/Reduce for Network Traffic Analysis (MR-Net Sger)
NeTS-NBD-SGER:用于网络流量分析的 Map/Reduce (MR-Net Sger)
  • 批准号:
    0823774
  • 财政年份:
    2008
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant

相似海外基金

CICI: RSARC: Secure Time for Cyberinfrastructure Security
CICI:RSARC:网络基础设施安全的安全时间
  • 批准号:
    1738902
  • 财政年份:
    2017
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CICI: RSARC: SECTOR: Building a Secure and Compliant Cyberinfrastructure for Translational Research
CICI:RSARC:部门:为转化研究构建安全且合规的网络基础设施
  • 批准号:
    1738965
  • 财政年份:
    2017
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CICI: RSARC: DICE - Data Insurance in the Cluster Environment
CICI:RSARC:DICE - 集群环境中的数据保险
  • 批准号:
    1738912
  • 财政年份:
    2017
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CICI: RSARC: Infrastructure Support for Securing Large-Scale Scientific Workflows
CICI:RSARC:确保大规模科学工作流程安全的基础设施支持
  • 批准号:
    1738929
  • 财政年份:
    2017
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
CICI: RSARC: Trustworthy Computing over Protected Datasets
CICI:RSARC:受保护数据集的可信计算
  • 批准号:
    1739000
  • 财政年份:
    2017
  • 资助金额:
    $ 99.72万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了