Denial of Service (DoS) attacks frequently happen on the Internet, paralyzing
Internet services and causing millions of dollars of financial loss. This work
presents NetFence, a scalable DoS-resistant network architecture. NetFence uses
a novel mechanism, secure congestion policing feedback, to enable robust
congestion policing inside the network. Bottleneck routers update the feedback
in packet headers to signal congestion, and access routers use it to police
senders' traffic.