MiddlePolice: Toward Enforcing Destination-Defined Policies in the Middle of the Internet
Zhuotao Liu, Hao Jin, Yih-Chun Hu, Michael D. Bailey
Abstract
Volumetric attacks, which overwhelm the bandwidth of a destination, are amongst the most common DDoS attacks today. One practical approach to addressing these attacks is to redirect all destination traffic (e.g., via DNS or BGP) to a third-party, DDoS-protection-as-a-service provider (e.g., CloudFlare) that is well provisioned and equipped with filtering mechanisms to remove attack traffic before passing the remaining benign traffic to the destination. An alternative approach is based on the concept of network capabilities, whereby source sending rates are determined by receiver consent, in the form of capabilities enforced by the network. While both third-party scrubbing services and network capabilities can be effective at reducing unwanted traffic at an overwhelmed destination, DDoS-protection-as-a-service solutions outsource all of the scheduling decisions (e.g., fairness, priority and attack identification) to the provider, while capability-based solutions require extensive modifications to existing infrastructure to operate. In this paper we introduce MiddlePolice, which seeks to marry the deployability of DDoS-protection-as-a-service solutions with the destination-based control of network capability systems. We show that by allowing feedback from the destination to the provider, MiddlePolice can effectively enforce destination-chosen policies, while requiring no deployment from unrelated parties.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c331a799-f992-4cdf-a727-d5030878e73fCited by top-tier papers4
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 99 citations
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang et al.S&P 2019 · 39 citations
- Deterrence of Intelligent DDoS via Multi-Hop Traffic DivergenceYuanjie Li, Hewu Li, Zhizheng Lv, Xingkun Yao et al.CCS 2021 · 11 citations
- Moderator: Moderating Text-to-Image Diffusion Models through Fine-grained Context-based PoliciesPeiran Wang, Qiyu Li, Longxuan Yu, Ziyao Wang et al.CCS 2024 · 2 citations
Related papers
- Anycast Agility: Network Playbooks to Fight DDoSA. S. M. Rizvi, Leandro M. Bertholdo, João M. Ceron, John S. HeidemannUSENIX Security 2022
- DDoS Detection at the Scale of One Hundred TbpsYunming Xiao, Xijun Luo, Youliang Jiang, Aike Wang et al.NSDI 2026 · 2 citations
- Zero-setup Intermediate-rate Communication Guarantees in a Global InternetMarc Wyss, Adrian PerrigUSENIX Security 2024 · 3 citations
- Efficient Policy-Rich Rate Enforcement with Phantom QueuesAmmar Tahir, Prateesh Goyal, Ilias Marinos, Mike Evans et al.SIGCOMM 2024 · 10 citations
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 71 citations
