{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/78589"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/78589","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"FlowPolice: enforcing congestion accountability to defend against DDoS attacks","abstract":"The student, Zhuotao Liu, submitted this Thesis for approval on 2015-03-10 at 15:01.","abstract_html":"The student, Zhuotao Liu, submitted this Thesis for approval on 2015-03-10 at 15:01.","abstract_has_math":false,"creators":["Liu, Zhuotao"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Hu, Yih-Chun"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2015,"date_issued":"2015-07-22T22:32:54Z","date_published":"2015-07-22T22:32:54Z","updated_at":"2026-07-22T22:26:12Z","subjects":["Distributed Denial of Service (DDoS) Attacks","Internet Security"],"languages":[],"rights":["Copyright 2015 Zhuotao Liu"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/78589","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Hu, Yih-Chun"]},{"key":"dc:creator","label":"Author","values":["Liu, Zhuotao"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2015-07-22T22:32:54Z","2017-07-23T09:15:34Z","2015-05","2015-03-16","2015-5"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Distributed Denial of Service (DDoS) Attacks","Internet Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2015 Zhuotao Liu"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/78589"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The student, Zhuotao Liu, submitted this Thesis for approval on 2015-03-10 at 15:01.","This Thesis was approved for publication on 2015-03-16 at 16:58.","DSpace SAF Submission Ingestion Package generated from Vireo submission #7743 on 2015-07-22 at 14:16:50","Made available in DSpace on 2015-07-22T22:32:54Z (GMT). No. of bitstreams: 2 Liu_Zhuotao.pdf: 1128680 bytes, checksum: 3dedae78510dcdb7a66caf1dbbf1278f (MD5) license.txt: 4059 bytes, checksum: 4d2de6b7507d637713f493665a56015a (MD5) Previous issue date: 2015-03-16","Defending the Internet against distributed denial of service (DDoS) attacks is a fundamental problem. Despite over a decade of research, little progress has been made on the real-world deployment of proposed approaches due to the prohibitive deployment hurdles. This thesis presents FlowPolice, a new DDoS defense mechanism capable of thwarting millions of attack flows, while requiring very lightweight deployment. Specifically, FlowPolice can immediately benefit the first deployed autonomous system (AS) without further deployment at other ASs, and a single deployed router can protect all downstream links that implement a simple prioritization mechanism. The design of FlowPolice suppresses attack traffic by forcing attackers to be accountable for congestion via proper rate limiting. To learn users’ congestion accountability, FlowPolice leverages a capability feedback mechanism so that the deploying router can make rate limiting decisions based only on its self-generated capability tags. We use theoretical analysis, large scale simulation and Linux implementation to demonstrate the effectiveness of FlowPolice. Specifically, the the- oretical analysis proves that FlowPolice ensures per-flow fair share at the bottleneck link. Our implementation shows that FlowPolice can scale up to handle very large scale DDoS attacks and introduces little packet process- ing overhead. We also perform detailed packet-level simulation to show that FlowPolice is effective to mitigate DDoS attacks.","Submission published under a 24 month embargo labeled 'U of I only', the embargo will last until 2017-05-01","The student, Zhuotao Liu, accepted the attached license on 2015-03-10 at 14:52.","Embargo set by: Seth Robbins for item 79830 Lift date: 2017-07-22T22:34:16Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 79830 on 2017-07-23T09:15:34Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["FlowPolice: enforcing congestion accountability to defend against DDoS attacks"]}]}],"canonical_facts":{"dc:contributor":["Hu, Yih-Chun"],"dc:creator":["Liu, Zhuotao"],"dc:date":["2015-07-22T22:32:54Z","2017-07-23T09:15:34Z","2015-05","2015-03-16","2015-5"],"dc:description":["The student, Zhuotao Liu, submitted this Thesis for approval on 2015-03-10 at 15:01.","This Thesis was approved for publication on 2015-03-16 at 16:58.","DSpace SAF Submission Ingestion Package generated from Vireo submission #7743 on 2015-07-22 at 14:16:50","Made available in DSpace on 2015-07-22T22:32:54Z (GMT). No. of bitstreams: 2 Liu_Zhuotao.pdf: 1128680 bytes, checksum: 3dedae78510dcdb7a66caf1dbbf1278f (MD5) license.txt: 4059 bytes, checksum: 4d2de6b7507d637713f493665a56015a (MD5) Previous issue date: 2015-03-16","Defending the Internet against distributed denial of service (DDoS) attacks is a fundamental problem. Despite over a decade of research, little progress has been made on the real-world deployment of proposed approaches due to the prohibitive deployment hurdles. This thesis presents FlowPolice, a new DDoS defense mechanism capable of thwarting millions of attack flows, while requiring very lightweight deployment. Specifically, FlowPolice can immediately benefit the first deployed autonomous system (AS) without further deployment at other ASs, and a single deployed router can protect all downstream links that implement a simple prioritization mechanism. The design of FlowPolice suppresses attack traffic by forcing attackers to be accountable for congestion via proper rate limiting. To learn users’ congestion accountability, FlowPolice leverages a capability feedback mechanism so that the deploying router can make rate limiting decisions based only on its self-generated capability tags. We use theoretical analysis, large scale simulation and Linux implementation to demonstrate the effectiveness of FlowPolice. Specifically, the the- oretical analysis proves that FlowPolice ensures per-flow fair share at the bottleneck link. Our implementation shows that FlowPolice can scale up to handle very large scale DDoS attacks and introduces little packet process- ing overhead. We also perform detailed packet-level simulation to show that FlowPolice is effective to mitigate DDoS attacks.","Submission published under a 24 month embargo labeled 'U of I only', the embargo will last until 2017-05-01","The student, Zhuotao Liu, accepted the attached license on 2015-03-10 at 14:52.","Embargo set by: Seth Robbins for item 79830 Lift date: 2017-07-22T22:34:16Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 79830 on 2017-07-23T09:15:34Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/78589"],"dc:rights":["Copyright 2015 Zhuotao Liu"],"dc:subject":["Distributed Denial of Service (DDoS) Attacks","Internet Security"],"dc:title":["FlowPolice: enforcing congestion accountability to defend against DDoS attacks"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:12Z"}