Security researchers develop DoS attack filter

Filtering software blocks hacker methods

Researchers have come up with host-based security software that blocks distributed denial-of-service attacks (DDoS) without swamping the memory and CPU of the host machines.

The filtering, called identity-based privacy-protected access control (IPCAF), can also prevent session hijacking, dictionary attacks and man-in-the-middle attacks, say researchers at Auburn University in their paper, "Modeling and simulations for Identity-Based Privacy-Protected Access Control Filter (IPCAF) capability to resist massive denial of service attacks."

This new method is suggested as a replacement for IP-address filtering, which is sometimes used to block DDoS attacks but is problematic because IP addresses can be spoofed, says Chwan-Hwa "John" Wu, a professor of electrical and computer engineering at Auburn and lead author of the paper.

The method also greatly reduces the resources attacked machines have to expend in order to figure out whether requests are legitimate, he says.

Under IPCAF authorised users and the servers they try to reach receive a one-time user ID and password to authenticate to each other. After that they cooperate to generate pseudo IDs and packet-field values for each successive packet so packets get authenticated one at a time.

The receiving machines simply check the field value in each packet in order to decide whether to reject it. Only after the filter value checks out are more memory and CPU resources allocated to further process the packets, Wu says.

DDoS attacks can cripple access servers and disable resources needed by legitimate users, resulting in recent high-profile outages at Twitter and Bitbuket.

The major challenge to attacked machines is that they must commit memory and CPU resources to figuring out whether requests are legitimate. Separate appliances can sort out bad packets and proxy legitimate ones to the attacked machines, but that requires capital outlay for the devices and ongoing maintenance and management, he says.

By contrast, IPCAF runs on servers and client machines and does its work with negligible impact on performance of the machines involved, he says. For instance, the CPU on a machine running IPCAF and processing legitimate requests during testing was 10.21%. That rose to 11.78% when the same machine was under attack, Wu says.

He says machines using Pentium-class processors can filter packets in 6 nanosec using IPCAF, whereas the same machines would take a few milliseconds to make the same decision using public key infrastructure. That's about a million times slower with PKI. The significance is that the machines can get attack packets out of the way quickly before they start backing up and degrading response times to the point that users notice, Wu says.

To conserve processing power, IPCAF employs a lightweight hashing method -- hash-based message authentication code (HMAC) -- to generate the filter value it will use to authenticate each successive packet.

He says during lab tests, when a 10Gbps link to a server was filled with legitimate traffic and then with attack packets, network latency increased by 30 nanosec. "For humans, there is no difference," he says. Users don't sense the attack is underway, he says, and it remains possible for network security teams to trace the command and control center behind attacks.

Wu says the goal of the research is to create a commercial version of the software for use in business networks, but was uncertain when that might happen. He and his colleagues are still working on how their software might trace the source of attacks.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan

Security star Fortinet sets price for IPO

Investors still have taste for tech.



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *