Top Banner
1 SENSS Security Service for the Internet Jelena Mirkovic (USC/ISI), Minlan Yu (USC), Ying Zhang (HP Labs), Sivaram Ramanathan (USC)
7

SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

Feb 05, 2018

Download

Documents

trandat
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

1

SENSSSecurityServicefortheInternet

JelenaMirkovic(USC/ISI),Minlan Yu(USC),YingZhang(HPLabs),Sivaram Ramanathan (USC)

Page 2: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

DDoS Attacks:LargeandPowerful

• DDoS attacksareincreasinginvolumeandfrequency(newrecord1.2Tbps)

• Disproportionatepowerinhandsofattacker– Attacksthatbringdownlarge,wellprovisionedvictimsoftenwieldedbyasinglepersonorsmallgroup(Spamhouse,Dyn,OVHandKrebs)

– Nospecialexperienceorcircumstance– Cheapforattacker,veryexpensiveforthevictim

• Enabledbylarge,distributedbotnets– Nosingleentity(centralizedordistributed)canwithstandthis,distributeddefensesamust

2

Page 3: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

Oursolution:SENSS

3

• Fullysoftwaresolution– easytodeploy• EnablesanyISPtoofferautomated servicesfor

DDoS diagnosisandmitigation- Naturallydistributed,secure,robusttomisbehavior- WorkswithexistingISPinfrastructure(SDN,Flowspec,Netflow)

• VictimqueriesitsownISPorremoteISPs- Aboutitsinboundtraffic,routestoitsprefixes- Thishelpsdetectbestpointsformitigation

• VictimasksselectISPsto:- Filtersomeofitsinboundtraffic(victimspecifiesheadersignature)

- Demotearoutethatmaycontainabottleneck

Page 4: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

SENSSModules

4

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

ST

client

clientserver

server

server

server

detector

detectorproxyblacklist aggregator

4

Page 5: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

SENSSAPIsatISPs

• ExposedasWebservices– Leverageexistingfunctionalitiesforrobustness(replication),

security(HTTPS),charging(e-commerce)

• Messageauthentication:Proofofauthorityforaprefix– E.g.,RPKI,aDBofknowncustomers,prefixesandpublickeys

• TLSforcommunicationsecurity

5

Type Fields Action/ReplyTrafficquery Flow,dir,obs_time Listof<tag,dir,volume>

Trafficfilter/allow Flow,dir,tag,duration Deployfilter/allowactions

Routequery Prefix List ofbestpathstoprefix

Routedemote Prefix,segment,duration Demoterouteswithgivensegment

Page 6: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

HowCanYouHelp?• Deployapassivemodule:

– Detector– learnhowoftenyouexperienceDDoS orparticipateinit

– Blacklistaggregator– getourfeedofsuspiciousprefixes• Deployanactivemodule:

– Server– automatefilterruledeploymentinmultipleswitches– Client+Detector– leverageyourISP’sDDoS solutionandtriggeritautomatically

• Lookingfor:– Experiencesfromtrenches,whatdoyoudonowforDoS?– One-timefeedbackonneeds,deployability,concerns– 1h/monthongoingfeedbackfromopsworld– Sitestopilotoursolutions

6

Page 7: SENSS - Internet2 · PDF fileOur solution: SENSS 3 • Fully software solution –easy to deploy • Enables any ISP to offer automatedservices for DDoSdiagnosis and mitigation

[email protected]

http://steel.isi.edu/Projects/SENSS/

Jelena Mirkovic Minlan Yu Ying Zhang SivaramRamanathan