Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP Routing
Jared M. Smith, Max Schuchard
Abstract
In this paper, we present Nyx, the first system to both effectively mitigate modern Distributed Denial of Service (DDoS) attacks regardless of the amount of traffic under adversarial control and function without outside cooperation or an Internet redesign. Nyx approaches the problem of DDoS mitigation as a routing problem rather than a filtering problem. This conceptual shift allows Nyx to avoid many of the common shortcomings of existing academic and commercial DDoS mitigation systems. By leveraging how Autonomous Systems (ASes) handle route advertisement in the existing Border Gateway Protocol (BGP), Nyx allows the deploying AS to achieve isolation of traffic from a critical upstream AS off of attacked links and onto alternative, uncongested, paths. This isolation removes the need for filtering or de-prioritizing attack traffic. Nyx controls outbound paths through normal BGP path selection, while return paths from critical ASes are controlled through the use of specific techniques we developed using existing traffic engineering principles and require no outside coordination. Using our own realistic Internet-scale simulator, we find that in more than 98% of cases our system can successfully route critical traffic around network segments under transit-link DDoS attacks; a new form of DDoS attack where the attack traffic never reaches the victim AS, thus invaliding defensive filtering, throttling, or prioritization strategies. More significantly, in over 95% of those cases, the alternate path provides complete congestion relief from transit-link DDoS. Nyx additionally provides complete congestion relief in over 75% of cases when the deployer is being directly attacked.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 646f2586-e322-4c7a-8d76-a7879042d60dCited by top-tier papers21
- Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable SwitchesZaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee et al.USENIX Security 2021 · 221 citations
- Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive AdversariesJiarong Xing, Wenqing Wu, Ang ChenUSENIX Security 2021 · 100 citations
- NetHide: Secure and Practical Network Topology ObfuscationRoland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever et al.USENIX Security 2018 · 84 citations
- Aggregate-based congestion control for pulse-wave DDoS defenseAlbert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent VanbeverSIGCOMM 2022 · 63 citations
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
Related papers
- The Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing AttacksMilad Nasr, Hadi Zolfaghari, Amir HoumansadrCCS 2017 · 43 citations
- Deterrence of Intelligent DDoS via Multi-Hop Traffic DivergenceYuanjie Li, Hewu Li, Zhizheng Lv, Xingkun Yao et al.CCS 2021 · 11 citations
- Zero-setup Intermediate-rate Communication Guarantees in a Global InternetMarc Wyss, Adrian PerrigUSENIX Security 2024 · 3 citations
- DNS Congestion Control in Adversarial SettingsHuayi Duan, Jihye Kim, Marc Wyss, Adrian PerrigSOSP 2024 · 2 citations
- NetSynergy: Mitigating Application-layer DDoS via Adaptive Access-Backbone CollaborationJunchen Pan, Kunpeng He, Shengnan Liu, Menghao Zhang et al.CCS 2026
