Show simple item record

dc.contributor.authorGummadi, Ramakrishna
dc.contributor.authorBalakrishnan, Hari
dc.contributor.authorManiatis, Petros
dc.contributor.authorRatnasamy, Sylvia
dc.date.accessioned2012-09-24T20:52:51Z
dc.date.available2012-09-24T20:52:51Z
dc.date.issued2009-04
dc.identifier.urihttp://hdl.handle.net/1721.1/73143
dc.description.abstractA large fraction of email spam, distributed denial-of-service (DDoS) attacks, and click-fraud on web advertisements are caused by traffic sent from compromised machines that form botnets. This paper posits that by identifying human-generated traffic as such, one can service it with improved reliability or higher priority, mitigating the effects of botnet attacks. The key challenge is to identify human-generated traffic in the absence of strong unique identities. We develop NAB (``Not-A-Bot''), a system to approximately identify and certify human-generated activity. NAB uses a small trusted software component called an attester, which runs on the client machine with an untrusted OS and applications. The attester tags each request with an attestation if the request is made within a small amount of time of legitimate keyboard or mouse activity. The remote entity serving the request sends the request and attestation to a verifier, which checks the attestation and implements an application-specific policy for attested requests. Our implementation of the attester is within the Xen hypervisor. By analyzing traces of keyboard and mouse activity from 328 users at Intel, together with adversarial traces of spam, DDoS, and click-fraud activity, we estimate that NAB reduces the amount of spam that currently passes through a tuned spam filter by more than 92%, while not flagging any legitimate email as spam. NAB delivers similar benefits to legitimate requests under DDoS and click-fraud attacks.en_US
dc.language.isoen_US
dc.publisherUSENIX Associationen_US
dc.relation.isversionofhttp://static.usenix.org/events/nsdi09/tech/full_papers/gummadi/gummadi.pdfen_US
dc.rightsCreative Commons Attribution-Noncommercial-Share Alike 3.0en_US
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/3.0/en_US
dc.sourceOther Repositoryen_US
dc.titleNot-a-Bot (NAB): Improving Service Availability in the Face of Botnet Attacksen_US
dc.typeArticleen_US
dc.identifier.citationGummadi, Ramakrishna et al. "Not-a-Bot (NAB): Improving Service Availability in the Face of Botnet Attacks." Proceedings of the 6th USENIX Symposium on Networked Systems Design and Implementation, NSDI ’09. April 22-24, 2009, Boston, Mass. p. 307-320. http://static.usenix.org/events/nsdi09/tech/en_US
dc.contributor.departmentMassachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratoryen_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Scienceen_US
dc.contributor.approverBalakrishnan, Hari
dc.contributor.mitauthorGummadi, Ramakrishna
dc.contributor.mitauthorBalakrishnan, Hari
dc.relation.journalProceedings of the 6th USENIX Symposium on Networked Systems Design and Implementation, NSDI ’09en_US
dc.eprint.versionAuthor's final manuscripten_US
dc.type.urihttp://purl.org/eprint/type/ConferencePaperen_US
dspace.orderedauthorsGummadi, Ramakrishna; Balakrishnan, Hari; Maniatis, Petros; Ratnasamy, Sylviaen_US
dc.identifier.orcidhttps://orcid.org/0000-0002-1455-9652
mit.licenseOPEN_ACCESS_POLICYen_US
mit.metadata.statusComplete


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record