Skip to main content
Journal cover image

A multi-layer framework for puzzle-based denial-of-service defense

Publication ,  Journal Article
Wang, XF; Reiter, MK
Published in: International Journal of Information Security
August 1, 2008

Client puzzles have been advocated as a promising countermeasure to denial-of-service (DoS) attacks in recent years. However, how to operationalize this idea in network protocol stacks still has not been sufficiently studied. In this paper, we describe our research on a multi-layer puzzle-based DoS defense architecture, which embeds puzzle techniques into both end-to-end and IP-layer services. Specifically, our research results in two new puzzle techniques: puzzle auctions for end-to-end protection and congestion puzzles for IP-layer protection. We present the designs of these approaches and evaluations of their efficacy. We demonstrate that our techniques effectively mitigate DoS threats to IP, TCP and application protocols; maintain full interoperability with legacy systems; and support incremental deployment. We also provide a game theoretic analysis that sheds light on the potential to use client puzzles for incentive engineering: the costs of solving puzzles on an attackers' behalf could motivate computer owners to more aggressively cleanse their computers of malware, in turn hindering the attacker from capturing a large number of computers with which it can launch DoS attacks. © Springer-Verlag 2007.

Duke Scholars

Published In

International Journal of Information Security

DOI

EISSN

1615-5270

ISSN

1615-5262

Publication Date

August 1, 2008

Volume

7

Issue

4

Start / End Page

243 / 263

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 15 Commerce, Management, Tourism and Services
  • 08 Information and Computing Sciences
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Wang, X. F., & Reiter, M. K. (2008). A multi-layer framework for puzzle-based denial-of-service defense. International Journal of Information Security, 7(4), 243–263. https://doi.org/10.1007/s10207-007-0042-x
Wang, X. F., and M. K. Reiter. “A multi-layer framework for puzzle-based denial-of-service defense.” International Journal of Information Security 7, no. 4 (August 1, 2008): 243–63. https://doi.org/10.1007/s10207-007-0042-x.
Wang XF, Reiter MK. A multi-layer framework for puzzle-based denial-of-service defense. International Journal of Information Security. 2008 Aug 1;7(4):243–63.
Wang, X. F., and M. K. Reiter. “A multi-layer framework for puzzle-based denial-of-service defense.” International Journal of Information Security, vol. 7, no. 4, Aug. 2008, pp. 243–63. Scopus, doi:10.1007/s10207-007-0042-x.
Wang XF, Reiter MK. A multi-layer framework for puzzle-based denial-of-service defense. International Journal of Information Security. 2008 Aug 1;7(4):243–263.
Journal cover image

Published In

International Journal of Information Security

DOI

EISSN

1615-5270

ISSN

1615-5262

Publication Date

August 1, 2008

Volume

7

Issue

4

Start / End Page

243 / 263

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 15 Commerce, Management, Tourism and Services
  • 08 Information and Computing Sciences