SAFE: a Scalable Filter-Based Packet Filtering Scheme

被引:0
|
作者
Lu Ning [1 ,2 ,3 ]
Hu Wenhao [1 ]
机构
[1] Northeastern Univ, Coll Informat Sci & Engn, Shenyang 110819, Liaoning, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100000, Peoples R China
[3] Nanjing Univ Informat Sci & Technol, Nanjing 210044, Jiangsu, Peoples R China
关键词
internet security; DoS attacks; filtering scheme; DDOS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Denial-of-Service (DoS) attacks have become the mainstream threat to the Internet service availability. The filter-based packet filtering is a key technology to defend against such attacks. Relying on the filtering location, the proposed schemes can be grouped into Victim-end Filtering and Source-end Filtering. The first scheme uses a single filtering router to block the attack flows near the victim, but does not take the factor that the filters are scarce resource into account, which causes the huge loss of legitimate flows; considering each router could contribute a few filters, the other extreme scheme pushes the filtering location back into each attack source so as to obtain ample filters, but this may incur the severe network transmission delay due to the abused filtering routers. Therefore, in this paper, we propose a scalable filter-based packet filtering scheme to balance the number of filtering routers and the available filters. Through emulating DoS scenarios based on the synthetic and real-world Internet topologies and further implementing the various filter-based packet filtering schemes on them, the results show that our scheme just uses fewer filtering routers to cut off all attack flows while minimizing the loss of legitimate flows.
引用
收藏
页码:163 / 177
页数:15
相关论文
共 50 条
  • [21] Cuckoo filter-based many-field packet classification using X-tree
    Abdulhassan, A. A.
    Ahmadi, M.
    JOURNAL OF SUPERCOMPUTING, 2019, 75 (09): : 5667 - 5687
  • [22] Kalman Filter-Based CMORPH
    Joyce, Robert J.
    Xie, Pingping
    JOURNAL OF HYDROMETEOROLOGY, 2011, 12 (06) : 1547 - 1563
  • [23] Single-phase solar grid-interfaced system with active filtering using adaptive linear combiner filter-based control scheme
    Singh, Yashi
    Hussain, Ikhlaq
    Singh, Bhim
    Mishra, Sukumar
    IET GENERATION TRANSMISSION & DISTRIBUTION, 2017, 11 (08) : 1976 - 1984
  • [24] Scalable implementation of particle filter-based visual object tracking on network-on-chip (NoC)
    Pinalkumar Engineer
    Rajbabu Velmurugan
    Sachin Patkar
    Journal of Real-Time Image Processing, 2020, 17 : 1117 - 1134
  • [25] An IP-traceback-based packet filtering scheme for eliminating DDoS attacks
    Wang, Yulong
    Sun, Rui
    Journal of Networks, 2014, 9 (04) : 874 - 881
  • [26] Scalable implementation of particle filter-based visual object tracking on network-on-chip (NoC)
    Engineer, Pinalkumar
    Velmurugan, Rajbabu
    Patkar, Sachin
    JOURNAL OF REAL-TIME IMAGE PROCESSING, 2020, 17 (05) : 1117 - 1134
  • [27] A novel scalable optical packet compression/decompression scheme
    Aleksic, S
    Krajinovic, V
    Bengi, K
    ECOC'01: 27TH EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION, VOLS 1-6, 2001, : 478 - 479
  • [28] An Efficient Bloom Filter-based Range Query Scheme Under Local Differential Privacy
    Zhang, Ellen Z.
    Guan, Yunguo
    Lu, Rongxing
    Zhang, Harry
    2023 IEEE 34TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, PIMRC, 2023,
  • [29] A DNS filter and switch for packet-filtering gateways
    Cheswick, B
    Bellovin, SM
    PROCEEDINGS OF THE SIXTH ANNUAL USENIX SECURITY SYMPOSIUM: FOCUSING ON APPLICATIONS OF CRYPTOGRAPHY, 1996, : 15 - 19
  • [30] Particle filter-based monitoring scheme for simulated bio-ethylene production process
    Ferreira Salardani, Luciana Souza
    Albuquerque, Lorrane Pains
    Justino da Costa, Jose Mir
    da Silva, Wellington Betencurte
    Sampaio Dutra, Julio Cesar
    INVERSE PROBLEMS IN SCIENCE AND ENGINEERING, 2019, 27 (05) : 648 - 668