DDoS Defense in Depth for DNS (DDIDD). Heidemann, J., Hardaker, W., Mirkovic, J., Rizvi, A., & Story, R. Invited talk at the Trusted CI Webinar, December, 2019. Paper abstract bibtex he DDIDD Project (DDoS Defense in Depth for DNS) is applying existing and developing new defenses against Distributed-Denial-of-Service attacks for operational DNS infrastructure. We are building a defense-in-depth approach to mitigate Distributed Denial-of-Service attacks for DNS servers, with approaches to filter spoofed traffic, identify known-good traffic when possible, and employ cloud-based scaling to handle the largest attacks. We are working with USC's B-Root team to test our approaches as a case study, and are making approaches open source as they become available. This talk will summarize the project and our overall approach, provide details about some of our early filters and filter selection, and describe where we plan to go in the remaining year.
@Misc{Heidemann19a,
author = "John Heidemann and Wes Hardaker and Jelena
Mirkovic and ASM Rizvi and Robert Story",
title = "{DDoS} Defense in Depth for {DNS} (DDIDD)",
howpublished = "Invited talk at the Trusted CI Webinar",
month = dec,
year = 2019,
sortdate = "2019-12-09",
project = "ant, ddidd, paaddos, diiner",
jsubject = "topology_modeling",
jlocation = "johnh: pafile",
keywords = "anti-DDoS, network security, B-Root, invited talks",
url = "https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.html",
pdfurl = "https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.pdf",
videourl = "https://youtu.be/g_IivqPLdQM",
myorganization = "USC/Information Sciences Institute",
copyrightholder = "authors",
abstract = "
he DDIDD Project (DDoS Defense in Depth for DNS) is
applying existing and developing new defenses against
Distributed-Denial-of-Service attacks for operational DNS
infrastructure. We are building a defense-in-depth approach to
mitigate Distributed Denial-of-Service attacks for DNS servers, with
approaches to filter spoofed traffic, identify known-good traffic when
possible, and employ cloud-based scaling to handle the largest
attacks. We are working with USC's B-Root team to test our approaches
as a case study, and are making approaches open source as they become
available. This talk will summarize the project and our overall
approach, provide details about some of our early filters and filter
selection, and describe where we plan to go in the remaining year.
",
}
Downloads: 0
{"_id":"Rm7ctF6JpjJAF3s2P","bibbaseid":"heidemann-hardaker-mirkovic-rizvi-story-ddosdefenseindepthfordnsddidd-2019","author_short":["Heidemann, J.","Hardaker, W.","Mirkovic, J.","Rizvi, A.","Story, R."],"bibdata":{"bibtype":"misc","type":"misc","author":[{"firstnames":["John"],"propositions":[],"lastnames":["Heidemann"],"suffixes":[]},{"firstnames":["Wes"],"propositions":[],"lastnames":["Hardaker"],"suffixes":[]},{"firstnames":["Jelena"],"propositions":[],"lastnames":["Mirkovic"],"suffixes":[]},{"firstnames":["ASM"],"propositions":[],"lastnames":["Rizvi"],"suffixes":[]},{"firstnames":["Robert"],"propositions":[],"lastnames":["Story"],"suffixes":[]}],"title":"DDoS Defense in Depth for DNS (DDIDD)","howpublished":"Invited talk at the Trusted CI Webinar","month":"December","year":"2019","sortdate":"2019-12-09","project":"ant, ddidd, paaddos, diiner","jsubject":"topology_modeling","jlocation":"johnh: pafile","keywords":"anti-DDoS, network security, B-Root, invited talks","url":"https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.html","pdfurl":"https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.pdf","videourl":"https://youtu.be/g_IivqPLdQM","myorganization":"USC/Information Sciences Institute","copyrightholder":"authors","abstract":"he DDIDD Project (DDoS Defense in Depth for DNS) is applying existing and developing new defenses against Distributed-Denial-of-Service attacks for operational DNS infrastructure. We are building a defense-in-depth approach to mitigate Distributed Denial-of-Service attacks for DNS servers, with approaches to filter spoofed traffic, identify known-good traffic when possible, and employ cloud-based scaling to handle the largest attacks. We are working with USC's B-Root team to test our approaches as a case study, and are making approaches open source as they become available. This talk will summarize the project and our overall approach, provide details about some of our early filters and filter selection, and describe where we plan to go in the remaining year. ","bibtex":"@Misc{Heidemann19a,\n\tauthor = \t\"John Heidemann and Wes Hardaker and Jelena\n Mirkovic and ASM Rizvi and Robert Story\",\n\ttitle = \t\"{DDoS} Defense in Depth for {DNS} (DDIDD)\",\n\thowpublished = \"Invited talk at the Trusted CI Webinar\",\n\tmonth = \tdec,\n\tyear = \t2019,\n\tsortdate = \t\"2019-12-09\", \n\tproject = \"ant, ddidd, paaddos, diiner\",\n\tjsubject = \"topology_modeling\",\n\tjlocation = \t\"johnh: pafile\",\n\tkeywords = \t\"anti-DDoS, network security, B-Root, invited talks\",\n\turl =\t\t\"https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.html\",\n\tpdfurl =\t\"https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.pdf\",\n\tvideourl = \"https://youtu.be/g_IivqPLdQM\",\n\tmyorganization =\t\"USC/Information Sciences Institute\",\n\tcopyrightholder = \"authors\",\n\tabstract = \"\nhe DDIDD Project (DDoS Defense in Depth for DNS) is\napplying existing and developing new defenses against\nDistributed-Denial-of-Service attacks for operational DNS\ninfrastructure. We are building a defense-in-depth approach to\nmitigate Distributed Denial-of-Service attacks for DNS servers, with\napproaches to filter spoofed traffic, identify known-good traffic when\npossible, and employ cloud-based scaling to handle the largest\nattacks. We are working with USC's B-Root team to test our approaches\nas a case study, and are making approaches open source as they become\navailable. This talk will summarize the project and our overall\napproach, provide details about some of our early filters and filter\nselection, and describe where we plan to go in the remaining year.\n\",\n}\n\n","author_short":["Heidemann, J.","Hardaker, W.","Mirkovic, J.","Rizvi, A.","Story, R."],"bibbaseid":"heidemann-hardaker-mirkovic-rizvi-story-ddosdefenseindepthfordnsddidd-2019","role":"author","urls":{"Paper":"https://ant.isi.edu/%7ejohnh/PAPERS/Heidemann19a.html"},"keyword":["anti-DDoS","network security","B-Root","invited talks"],"metadata":{"authorlinks":{}}},"bibtype":"misc","biburl":"https://bibbase.org/f/dHevizJoWEhWowz8q/johnh-2023-2.bib","dataSources":["YLyu3mj3xsBeoqiHK","qoQdxm5c8Br34G4md","fLZcDgNSoSuatv6aX","fxEParwu2ZfurScPY","5522rqg4rez4tcnch","7nuQvtHTqKrLmgu99"],"keywords":["anti-ddos","network security","b-root","invited talks"],"search_terms":["ddos","defense","depth","dns","ddidd","heidemann","hardaker","mirkovic","rizvi","story"],"title":"DDoS Defense in Depth for DNS (DDIDD)","year":2019}