NetFence: Preventing Internet Denial of Service from Inside Out

被引:50
|
作者
Liu, Xin [1 ]
Yang, Xiaowei [1 ]
Xia, Yong
机构
[1] Duke Univ, Dept Comp Sci, Durham, NC 27706 USA
基金
美国国家科学基金会;
关键词
Design; Security; Internet; Denial-of-Service; Capability; Congestion Policing;
D O I
10.1145/1851275.1851214
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Denial of Service (DoS) attacks frequently happen on the Internet, paralyzing Internet services and causing millions of dollars of financial loss. This work presents NetFence, a scalable DoS-resistant network architecture. NetFence uses a novel mechanism, secure congestion policing feedback, to enable robust congestion policing inside the network. Bottleneck routers update the feedback in packet headers to signal congestion, and access routers use it to police senders' traffic. Targeted DoS victims can use the secure congestion policing feedback as capability tokens to suppress unwanted traffic. When compromised senders and receivers organize into pairs to congest a network link, NetFence provably guarantees a legitimate sender its fair share of network resources without keeping per-host state at the congested link. We use a Linux implementation, ns-2 simulations, and theoretical analysis to show that NetFence is an effective and scalable DoS solution: it reduces the amount of state maintained by a congested router from per-host to at most per-(Autonomous System).
引用
收藏
页码:255 / 266
页数:12
相关论文
共 50 条
  • [1] Preventing Internet denial-of-service with capabilities
    Anderson, T
    Roscoe, T
    Wetherall, D
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (01) : 39 - 44
  • [2] Out of Kilter: Holistic Exploitation of Denial of Service in Internet of Things
    Setikere, Suhas
    Sachidananda, Vinay
    Elovici, Yuval
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT I, 2018, 254 : 43 - 52
  • [3] COMMENT ON DENIAL INSIDE OUT
    WEINSTEIN, EA
    [J]. PSYCHIATRY, 1969, 32 (02) : 189 - +
  • [4] Preventing denial of service attacks on Quality of Service
    Fulp, E
    Fu, Z
    Reeves, DS
    Wu, SF
    Zhang, XB
    [J]. DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL II, PROCEEDINGS, 2001, : 159 - 172
  • [5] Preventing parasites inside and out
    不详
    [J]. VETERINARY RECORD, 2015, 176 (15) : 394
  • [6] New denial of service attack on Internet
    Hancock, B
    [J]. COMPUTERS & SECURITY, 2000, 19 (04) : 309 - 310
  • [7] A SPECIFICATION AND VERIFICATION METHOD FOR PREVENTING DENIAL OF SERVICE
    YU, CF
    GLIGOR, VD
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1990, 16 (06) : 581 - 592
  • [8] Preventing service oriented denial of service (PreSODoS): A proposed approach
    Padmanabhuni, Srinivas
    Singh, Vineet
    Kumar, K. M. Senthil
    Chatterjee, Abhishek
    [J]. ICWS 2006: IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2006, : 577 - +
  • [9] Protecting the Internet from distributed denial-of-service attacks: A proposal
    Crocker, SD
    [J]. PROCEEDINGS OF THE IEEE, 2004, 92 (09) : 1375 - 1381
  • [10] Internet of Things and Distributed Denial of Service Mitigation
    Ali, Mohammed AlSaudi
    Motawa, Dyaa
    Al-Harby, Fahad
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 26 - 36