IP easy-pass: Edge resource access control

被引:0
|
作者
Wang, HN [1 ]
Bose, A [1 ]
El-Gendy, M [1 ]
Shin, KG [1 ]
机构
[1] Coll William & Mary, Dept Comp Sci, Williamsburg, VA 23187 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Providing real-time communication services to multimedia applications and subscription-based Internet access often requires sufficient network resources to be reserved for real-time traffic. However, the reserved network resource is susceptible to resource theft and abuse. Without a resource access control mechanism that can efficiently differentiate legitimate real-time traffic from attacking packets, the traffic conditioning and policing enforced at ISP (Internet Service Provider) edge routers cannot protect the reserved network resource from embezzlement. On the contrary, the traffic policing at edge routers aggravates their vulnerability to flooding attacks by blindly dropping packets. In this paper, we propose a fast and light-weighted IP network-edge resource access control mechanism, called IP Easy-pass, to prevent unauthorized access to reserved network resources at edge devices. We attach a unique pass to each legitimate real-time packet so that an ISP edge router can validate the legitimacy of an incoming IP packet very quickly and simply by checking its pass. We present the generation of Easy-pass, its embedding, and verification procedures. We implement the IP Easy-pass mechanism in the Linux kernel, analyze its effectiveness against packet forgery and resource embezzlement attempts. Finally, we measure the overhead incurred by Easy-pass.
引用
收藏
页码:2583 / 2593
页数:11
相关论文
共 50 条
  • [41] Verifying resource access control on mobile interactive devices
    Besson, Frederic
    Dufay, Guillaume
    Jensen, Thomas
    Pichardie, David
    JOURNAL OF COMPUTER SECURITY, 2010, 18 (06) : 971 - 998
  • [42] Sensitivity analysis on resource access control in mobile networks
    Chen, H
    Cheng, CC
    Chi, MH
    Yeh, HH
    INTERNET MULTIMEDIA MANAGEMENT SYSTEMS V, 2004, 5601 : 214 - 224
  • [43] Resource-centric Dynamic Access Control in Cloud
    Su, Mang
    Fu, Anmin
    Yu, Yan
    Shi, Guozhen
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1957 - 1962
  • [44] A formal logic for shared resource access control in the grid
    Li, BY
    Rao, RN
    You, JY
    Li, ML
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 498 - 505
  • [45] Resource access and mobility control with dynamic privileges acquisition
    Gorla, D
    Pugliese, R
    AUTOMATA, LANGUAGES AND PROGRAMMING, PROCEEDINGS, 2003, 2719 : 119 - 132
  • [46] Resource allocation for edge computing over fibre-wireless access networks
    Wang, Qingtian
    Shou, Guochu
    Liu, Jing
    Liu, Yaqiong
    Hu, Yihong
    Guo, Zhigang
    IET COMMUNICATIONS, 2019, 13 (17) : 2848 - 2856
  • [47] Computation Offloading in Resource-Constrained Multi-Access Edge Computing
    Li, Kexin
    Wang, Xingwei
    He, Qiang
    Wang, Jielei
    Li, Jie
    Zhan, Siyu
    Lu, Guoming
    Dustdar, Schahram
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (11) : 10665 - 10677
  • [48] Resource allocation for UAV-enabled multi-access edge computing
    Falcao, Marcos
    Souza, Caio Bruno
    Balieiro, Andson
    Dias, Kelvin
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (15): : 22770 - 22802
  • [49] Resource Scheduling Optimization under Multi-Access Edge Computing Architecture
    Bao, Lixia
    Yang, Yue
    Mao, Jiaqing
    Gao, Zhibo
    Wu, Zhizhou
    CICTP 2022: INTELLIGENT, GREEN, AND CONNECTED TRANSPORTATION, 2022, : 668 - 678
  • [50] resource sharing and incentive mechanism for multi-access edge computing networks
    Song L.
    Sun G.
    Sun J.
    Yu H.
    Tongxin Xuebao/Journal on Communications, 2023, 44 (11): : 67 - 78