Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures

被引:7
|
作者
An, Hyok [1 ]
Na, Yoonjong [1 ]
Lee, Heejo [1 ]
Perrig, Adrian [2 ]
机构
[1] Korea Univ, Dept Comp Sci & Engn, Seoul 02841, South Korea
[2] Swiss Fed Inst Technol, Dept Comp Sci, CH-8092 Zurich, Switzerland
关键词
network security; multi-path routing; high availability; Internet-scale evaluation; SELF-AWARE NETWORKS;
D O I
10.3390/electronics10111240
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The current state of security and availability of the Internet is far from being commensurate with its importance. The number and strength of DDoS attacks conducted at the network layer have been steadily increasing. However, the single path (SP) routing used in today's Internet lacks a mitigation scheme to rapidly recover from network attacks or link failure. In case of a link failure occurs, it can take several minutes until failover. In contrast, multi-path routing can take advantage of multiple alternative paths and rapidly switch to another working path. According to the level of available path control, we classfy the multi-path routing into two types, first-hop multi-path (FMP) and multi-hop multi-path (MMP) routing. Although FMP routing supported by networks, such as SD-WAN, shows marginal improvements over the current SP routing of the Internet, MMP routing supported by a global Internet architecture provides strong improvement under network attacks and link failure. MMP routing enables changing to alternate paths to mitigate the network problem in other hops, which cannot be controlled by FMP routing. To show this comparison with practical outcome, we evaluate network performance in terms of latency and loss rate to show that MMP routing can mitigate Internet hazards and provide high availability on global networks by 18 participating ASes in six countries. Our evaluation of global networks shows that, if network attacks or failures occur in other autonomous systems (ASes) that FMP routing cannot avoid, it is feasible to deal with such problems by switching to alternative paths by using MMP routing. When the global evaluation is under a transit-link DDoS attack, the loss rates of FMP that pass the transit-link are affected significantly by a transit-link DDoS attack, but the other alternative MMP paths show stable status under the DDoS attack with proper operation.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Multi-Path Routing in the Jellyfish Network
    ALzaid, Zaid
    Bhowmik, Saptarshi
    Yuan, Xin
    [J]. 2021 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW), 2021, : 832 - 841
  • [2] No Way to Evade: Detecting Multi-Path Routing Attacks for NIDS
    Liu, Likun
    Shi, Jiantao
    Zhang, Hongli
    Yu, Xiangzhan
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [3] Multi-Path Routing and Resource Allocation in Active Network
    XU Wu-ping
    [J]. Wuhan University Journal of Natural Sciences, 2005, (02) : 398 - 404
  • [4] Multi-Path Routing for a Cognitive Wireless Mesh Network
    Javadi, Farshad
    Jamalipour, Abbas
    [J]. RWS: 2009 IEEE RADIO AND WIRELESS SYMPOSIUM, 2009, : 223 - 226
  • [5] Network decomposition and multi-path routing optimal control
    Bruni, Carlo
    Priscoli, Francesco Delli
    Koch, Giorgio
    Pimpinella, Laura
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2013, 24 (02): : 154 - 165
  • [6] The Multi-Path Routing Problem in the Software Defined Network
    Liu, Yilan
    Pan, Yun
    Yang, Muxi
    Wang, Wenqing
    Fang, Chi
    Jiang, Ruijuan
    [J]. 2015 11TH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION (ICNC), 2015, : 250 - 254
  • [7] Collaborative in-network caching for multi-path routing
    Miyoshi, Yuta
    Wada, Takuya
    Hirata, Kouji
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2017,
  • [8] Multi-Path BGP (MBGP): A Solution for Improving Network Bandwidth Utilization and Defense against Link Failures in Inter-Domain Routing
    Fujinoki, Hiroshi
    [J]. PROCEEDINGS OF THE 2008 16TH INTERNATIONAL CONFERENCE ON NETWORKS, 2008, : 288 - 293
  • [9] A Multi-Path Approach to Protect DNS Against DDoS Attacks
    Alouneh, Sahel
    [J]. Journal of Cyber Security and Mobility, 2023, 12 (04): : 569 - 588
  • [10] Analysis of multi-path routing
    Cidon, I
    Rom, R
    Shavitt, Y
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 1999, 7 (06) : 885 - 896