{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/46463"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/46463","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Application-level distributed denial of service prevention in a replicated system","abstract":"This paper presents the design and implementation of DFQ (Distributed Fair Queueing), a distributed system for defending a replicated set of HTTP servers against application-level distributed denial of service (DDoS) attacks. By using a modification of weighted fair queueing, all clients are guaranteed a fair share of the servers. no matter how many or which servers they connect to. DFQ continues to provide fair service even against malicious clients who are able to spoof additional IP addresses. It is also capable of accommodating HTTP proxies, which regularly provide many times more traffic than a single host. Such properties are desirable for package management servers and the like, whose responsiveness in the presence of flash crowds and malicious attackers is paramount to the security of the overall system.","abstract_html":"This paper presents the design and implementation of DFQ (Distributed Fair Queueing), a distributed system for defending a replicated set of HTTP servers against application-level distributed denial of service (DDoS) attacks. By using a modification of weighted fair queueing, all clients are guaranteed a fair share of the servers. no matter how many or which servers they connect to. DFQ continues to provide fair service even against malicious clients who are able to spoof additional IP addresses. It is also capable of accommodating HTTP proxies, which regularly provide many times more traffic than a single host. Such properties are desirable for package management servers and the like, whose responsiveness in the presence of flash crowds and malicious attackers is paramount to the security of the overall system.","abstract_has_math":false,"creators":["Vandiver, Alexander M"],"institution":"Massachusetts Institute of Technology","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science.","school":null,"contributors":[],"advisors":["Hari Balakrishnan."],"committee_chairs":[],"committee_members":[],"year":2007,"date_issued":"2007","date_published":"2007","updated_at":"2026-07-22T22:22:30Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/1721.1/46463","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Hari Balakrishnan."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Vandiver, Alexander M"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2009-08-26T16:29:01Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2009-08-26T16:29:01Z"]},{"key":"dc:date.issued","label":"Date","values":["2007"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/1721.1/46463"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis (M. Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, 2007.","Includes bibliographical references (p. 35-38)."]},{"key":"dc:description.abstract","label":"Abstract","values":["This paper presents the design and implementation of DFQ (Distributed Fair Queueing), a distributed system for defending a replicated set of HTTP servers against application-level distributed denial of service (DDoS) attacks. By using a modification of weighted fair queueing, all clients are guaranteed a fair share of the servers. no matter how many or which servers they connect to. DFQ continues to provide fair service even against malicious clients who are able to spoof additional IP addresses. It is also capable of accommodating HTTP proxies, which regularly provide many times more traffic than a single host. Such properties are desirable for package management servers and the like, whose responsiveness in the presence of flash crowds and malicious attackers is paramount to the security of the overall system."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M.Eng."]},{"key":"dc:title","label":"Title","values":["Application-level distributed denial of service prevention in a replicated system"]}]}],"canonical_facts":{"dc:contributor.advisor":["Hari Balakrishnan."],"dc:contributor.department":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."],"dc:contributor.other":["Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science."],"dc:creator":["Vandiver, Alexander M"],"dc:date.accessioned":["2009-08-26T16:29:01Z"],"dc:date.available":["2009-08-26T16:29:01Z"],"dc:date.issued":["2007"],"dc:description":["Thesis (M. Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, 2007.","Includes bibliographical references (p. 35-38)."],"dc:description.abstract":["This paper presents the design and implementation of DFQ (Distributed Fair Queueing), a distributed system for defending a replicated set of HTTP servers against application-level distributed denial of service (DDoS) attacks. By using a modification of weighted fair queueing, all clients are guaranteed a fair share of the servers. no matter how many or which servers they connect to. DFQ continues to provide fair service even against malicious clients who are able to spoof additional IP addresses. It is also capable of accommodating HTTP proxies, which regularly provide many times more traffic than a single host. Such properties are desirable for package management servers and the like, whose responsiveness in the presence of flash crowds and malicious attackers is paramount to the security of the overall system."],"dc:description.degree":["M.Eng."],"dc:identifier.uri":["http://hdl.handle.net/1721.1/46463"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["Application-level distributed denial of service prevention in a replicated system"],"dc:type":["Thesis"]},"updated_at":"2026-07-22T22:22:30Z"}