SAFE: a Scalable Filter-Based Packet Filtering Scheme

被引:0
|
作者
Lu Ning [1 ,2 ,3 ]
Hu Wenhao [1 ]
机构
[1] Northeastern Univ, Coll Informat Sci & Engn, Shenyang 110819, Liaoning, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100000, Peoples R China
[3] Nanjing Univ Informat Sci & Technol, Nanjing 210044, Jiangsu, Peoples R China
关键词
internet security; DoS attacks; filtering scheme; DDOS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Denial-of-Service (DoS) attacks have become the mainstream threat to the Internet service availability. The filter-based packet filtering is a key technology to defend against such attacks. Relying on the filtering location, the proposed schemes can be grouped into Victim-end Filtering and Source-end Filtering. The first scheme uses a single filtering router to block the attack flows near the victim, but does not take the factor that the filters are scarce resource into account, which causes the huge loss of legitimate flows; considering each router could contribute a few filters, the other extreme scheme pushes the filtering location back into each attack source so as to obtain ample filters, but this may incur the severe network transmission delay due to the abused filtering routers. Therefore, in this paper, we propose a scalable filter-based packet filtering scheme to balance the number of filtering routers and the available filters. Through emulating DoS scenarios based on the synthetic and real-world Internet topologies and further implementing the various filter-based packet filtering schemes on them, the results show that our scheme just uses fewer filtering routers to cut off all attack flows while minimizing the loss of legitimate flows.
引用
收藏
页码:163 / 177
页数:15
相关论文
共 50 条
  • [1] SAFE: a Scalable Filter-Based Packet Filtering Scheme
    LU Ning
    HU Wenhao
    China Communications, 2016, (02) : 163 - 177
  • [2] SAFE: a Scalable Filter-Based Packet Filtering Scheme
    LU Ning
    HU Wenhao
    中国通信, 2016, 13 (02) : 163 - 177
  • [3] hdFilter: Toward Faster Bloom Filter-based Packet Forwarding
    Lee, HyunYong
    Nakao, Akihiro
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [4] Bloom Filter-Based Scalable Multicast: Methodology, Design and Application
    Tian, Xiaohua
    Cheng, Yu
    IEEE NETWORK, 2013, 27 (06): : 89 - 94
  • [5] Hybrid resampling scheme for particle filter-based inversion
    Zafar, Taimoor
    Mairaj, Tariq
    Alam, Anzar
    Rasheed, Haroon
    IET SCIENCE MEASUREMENT & TECHNOLOGY, 2020, 14 (04) : 396 - 406
  • [6] Filter-based signal collection scheme in compressed sensing
    Wang, T. (wangtianjing@njut.edu.cn), 2013, Science Press (34):
  • [7] Shock filter-based morphological scheme for texture enhancement
    Chakraborty, Niladri
    Subudhi, Priyambada
    Mukhopadhyay, Susanta
    IET IMAGE PROCESSING, 2019, 13 (04) : 653 - 662
  • [8] A NEURAL FILTER-BASED SCHEME FOR SYNCHRONIZING CHAOTIC SYSTEMS
    Guo, Yu
    Wang, Fei
    Lo, Farnes Ting-Ho
    2017 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2017, : 4666 - 4670
  • [9] Bloom filter-based lightweight private matching scheme
    Wan, Sheng
    He, Yuan-Yuan
    Li, Feng-Hua
    Niu, Ben
    Li, Hui
    Wang, Xin-Yu
    Tongxin Xuebao/Journal on Communications, 2015, 36 (12):
  • [10] Speech Enhancement by Kalman Filtering with a Particle Filter-Based Preprocessor
    Lee, Yun-Kyung
    Jung, Gyeo-Woon
    Kwon, Oh-Wook
    2013 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2013, : 340 - 341