Protecting Content Distribution Networks from Denial of Service Attacks

Denial of service (DoS) attacks continue to be a daunting challenge
for service providers on the Internet. Recent work on countering these
attacks has focused primarily on attacks at a single server location
or on network resources. Increasingly, however, high-volume sites are
distributed using content distribution networks (CDNs). In this
paper, we develop two mechanisms to deter DoS attacks against
CDN-hosted Web sites and CDN infrastructure servers. First, we propose
a novel CDN request routing algorithm which allows CDN servers to
effectively distinguish attack traffic from legitimate requests. Our
scheme, based on a keyed hash function, significantly improves the
resilience of CDNs to DoS attacks. Second, we introduce several site
allocation algorithms based on binary codes which insure that an
attack on one hosted Web site will have a limited impact on other
hosted sites. Our scheme {\em guarantees} that a specified minimum
number of servers remain available for other sites even when the
intended victim is successfully attacked. Together, our schemes
significantly improve the resilience of CDN-hosted Web sites, and
complement other work on countering DoS and distributed DoS attacks.

By: Kang-Won Lee, Suresh N. Chari, Anees A. Shaikh, Sambit Sahu, Pau-Chen Cheng

Published in: RC22566 in 2002

LIMITED DISTRIBUTION NOTICE:

This Research Report is available. This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). I have read and understand this notice and am a member of the scientific community outside or inside of IBM seeking a single copy only.

RC22566.pdf

Questions about this service can be mailed to reports@us.ibm.com .