Mitigating Congestion-Based Denial of Service Attacks with Active Queue Management

被引:0
|
作者
Bedi, Harkeerat [1 ]
Roy, Sankardas [2 ]
Shiva, Sajjan [1 ]
机构
[1] Univ Memphis, Dept Comp Sci, Memphis, TN 38152 USA
[2] Kansas State Univ, Dept Comp & Informat Sci, Manhattan, KS 66506 USA
关键词
ALGORITHM; BLUE;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Denial of service (DoS) attacks are currently one of the biggest risks any organization connected to the Internet can face. Hence, the congestion handling techniques at its edge router(s), such as active queue management (AQM) schemes must consider possibilities of such attacks. Ideally, an AQM scheme should (a) ensure that each network flow gets its fair share of bandwidth, and (b) identify attack flows so that corrective actions (e.g. drop flooding traffic) can be explicitly taken against them to further mitigate the DoS attacks. This paper presents a proof-of-concept work on devising such an AQM scheme, which we name Deterministic Fair Sharing (DFS). Most of the existing AQM schemes do not achieve the above goals or have a significant room for improvement. DFS uses the concept of weighted fair share (wfs) which allows it to dynamically self-adjust the router buffer usage based on the current level of congestion, while assuring fairness among flows and aiding in identifying the malicious ones. We demonstrate the performance of DFS via extensive simulation and compare against other existing AQM techniques.
引用
收藏
页码:1440 / 1445
页数:6
相关论文
共 50 条
  • [1] An Active Queue Management based Deterministic Denial of Service Prevention
    Bilal, Saif
    Abbas, Ghulam
    Abbas, Ziaul Haq
    [J]. 2017 13TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES (ICET 2017), 2017,
  • [2] Mitigating denial of service attacks: A tutorial
    Molsa, Jarmo
    [J]. JOURNAL OF COMPUTER SECURITY, 2005, 13 (06) : 807 - 837
  • [3] Performance Analysis of a Queue with Congestion-Based Staffing Policy
    Zhang, Zhe George
    [J]. MANAGEMENT SCIENCE, 2009, 55 (02) : 240 - 251
  • [4] Mitigating denial of service attacks with password puzzles
    Ma, M
    [J]. ITCC 2005: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, VOL 2, 2005, : 621 - 626
  • [5] Developing modified congestion index and congestion-based level of service
    Gore, Ninad
    Arkatkar, Shriniwas
    Joshi, Gaurang
    Antoniou, Constantinos
    [J]. TRANSPORT POLICY, 2023, 131 : 97 - 119
  • [6] Mitigating distributed denial of service attacks in satellite networks
    Usman, Muhammad
    Qaraqe, Marwa
    Asghar, Muhammad Rizwan
    Shafique Ansari, Imran
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2020, 31 (06):
  • [7] Utilization of blockchain for mitigating the distributed denial of service attacks
    Singh, Rajeev
    Tanwar, Sudeep
    Sharma, Teek Parval
    [J]. SECURITY AND PRIVACY, 2020, 3 (03)
  • [8] Mitigating Denial of Service (DoS) Attacks in OpenFlow Networks
    Oktian, Yustus Eko
    Lee, SangGon
    Lee, HoonJae
    [J]. 2014 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2014, : 325 - 330
  • [9] Mitigating application layer distributed denial of service attacks via effective trust management
    Department of Computer Science, National University of Defense Technology, China
    不详
    不详
    [J]. IET Commun., 1751, 16 (1952-1962):
  • [10] Mitigating application layer distributed denial of service attacks via effective trust management
    Yu, J.
    Fang, C.
    Lu, L.
    Li, Z.
    [J]. IET COMMUNICATIONS, 2010, 4 (16) : 1952 - 1962