Critical servers can be secured against distributed denial of service (DDoS) attacks using proof of work (PoW) systems assisted by an Artificial Intelligence (AI) that learns contextual network request patterns. In this work, we introduce CAPoW, a context-aware anti-DDoS framework that injects latency adaptively during communication by utilizing context-aware PoW puzzles. In CAPoW, a security professional can define relevant request context attributes which can be learned by the AI system. These contextual attributes can include information about the user request, such as IP address, time, flow-level information, etc., and are utilized to generate a contextual score for incoming requests that influence the hardness of a PoW puzzle. These puzzles need to be solved by a user before the server begins to process their request. Solving puzzles slow down the volume of incoming adversarial requests. Additionally, the framework compels the adversary to incur a cost per request, hence making it expensive for an adversary to prolong a DDoS attack. We include the theoretical foundations of the CAPoW framework along with a description of its implementation and evaluation.
翻译:关键服务器可通过结合人工智能(AI)的PoW系统抵御分布式拒绝服务(DDoS)攻击,其中AI学习上下文相关的网络请求模式。本文提出CAPoW——一种利用上下文感知PoW谜题自适应注入通信延迟的反DDoS框架。在CAPoW中,安全专家可定义需由AI系统学习的相关请求上下文属性。这些上下文属性可包含用户请求信息(如IP地址、时间、流级信息等),并用于生成影响PoW谜题难度的请求上下文评分。用户需在服务器处理其请求前完成谜题求解。求解谜题的过程可降低恶意请求的流入速率。此外,该框架强制攻击者承担每次请求的成本,从而增加其持续发动DDoS攻击的代价。本文包含CAPoW框架的理论基础,以及其实现与评估的详细描述。