White Papers

Minimizing Collateral Damage by Proactive Surge Protection

Category: Security

Tags: psp, ddos, network

Overview Existing mechanisms for defending against Distributed Denial-of-Service (DDoS) attacks are generally reactive in nature. However, the onset of large-scale bandwidth-based attacks can occur suddenly, potentially knocking out substantial parts of a network before reactive defenses can respond. Even for traffic flows that are not under direct attack, significant collateral damage will result if these flows pass through links that are common to attack routes. This paper presents a Proactive-Surge-Protection (PSP) mechanism that aims to provide a broad first line of defense against DDoS attacks. Their solution aims to minimize collateral damage by providing bandwidth isolation between traffic flows. This isolation is achieved through a combination of traffic forecasting, proportional allocation of network capacity, metering and tagging of packets at the network perimeter, and preferential dropping of packets inside the network.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Association for Computing Machinery
File Format
PDF
Date Published
May 29, 2009
Format
White Papers
Topics
Denial of Service, Network Security, Security Management

Similiar White Papers

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

The X-Force Threat Insight Quarterly (Threat IQ) highlights the most significant threats and challenges facing security

Publisher: Internet Security Systems  |  Tags: homeland security, security flaws, voip

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

An independent report by ICSA Labs on the performance of ISS' VoIP-enabled Intrusion Prevention devices

This technical product evaluation is focused on the ISS VoIP-enabled Intrusion Prevention devices. These are built to su

Publisher: Internet Security Systems  |  Tags: voip

Cisco - Strategies to Protect Against Distributed Denial of Service (DDoS) Attacks

Cisco - Strategies to Protect Against Distributed Denial of Service (DDoS) Attacks

In order to facilitate Distributed Denial of Service (DDoS), the attackers need to have several hundred to several thous

Publisher: Cisco Systems  |  Tags: ddos, linux

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

Jargon, jargon, jargon. Find out what the IT industries acronyms really mean

ISS provide you with a simple glossary of major VoIP terms. What do they really mean, when can they be used? Make yourse

Publisher: Internet Security Systems  |  Tags: voip

IT's New Role: Defining and Managing Risk

IT's New Role: Defining and Managing Risk

This article explores how a Security Risk Management (SRM) approach can protect your company from the most severe threat

Publisher: McAfee  |  Tags: srm

Association for Computing Machinery White Papers

Managing ETL Processes

Managing ETL Processes

ETL tools allow the definition of sometimes complex processes to extract, transform, and load heterogeneous data into a

Publisher: Association for Computing Machinery  |  Tags: data, data integration, data warehouse, management

GPS-Free Node Localization in Mobile Wireless Sensor Networks

GPS-Free Node Localization in Mobile Wireless Sensor Networks

An important problem in mobile ad-hoc wireless sensor networks is the localization of individual nodes, i.e., each node'

Publisher: Association for Computing Machinery  |  Tags: gps, infrastructure, network

A Black-Box Approach for Web Application SLA

A Black-Box Approach for Web Application SLA

Web servers nowadays have to cope with unprecedented amounts of workload, due to increasing popularity and complexity; i

Publisher: Association for Computing Machinery  |  Tags: applications, server

Load Balancing for Multimedia Streaming in Heterogeneous Peer-to-Peer Systems

Load Balancing for Multimedia Streaming in Heterogeneous Peer-to-Peer Systems

Multimedia streaming of mostly user generated content is an ongoing trend, not only since the upcoming of Last.fm and Yo

Publisher: Association for Computing Machinery  |  Tags: user generated, user generated content, youtube

Multiobjective Network Design for Realistic Traffic Models

Multiobjective Network Design for Realistic Traffic Models

Network topology design problems find application in several real life scenarios. However, most designs in the past eith

Publisher: Association for Computing Machinery  |  Tags: network, realistic