SAFE: a Scalable Filter-Based Packet Filtering Scheme

被引:0
|
作者
Lu Ning [1 ,2 ,3 ]
Hu Wenhao [1 ]
机构
[1] Northeastern Univ, Coll Informat Sci & Engn, Shenyang 110819, Liaoning, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100000, Peoples R China
[3] Nanjing Univ Informat Sci & Technol, Nanjing 210044, Jiangsu, Peoples R China
关键词
internet security; DoS attacks; filtering scheme; DDOS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Denial-of-Service (DoS) attacks have become the mainstream threat to the Internet service availability. The filter-based packet filtering is a key technology to defend against such attacks. Relying on the filtering location, the proposed schemes can be grouped into Victim-end Filtering and Source-end Filtering. The first scheme uses a single filtering router to block the attack flows near the victim, but does not take the factor that the filters are scarce resource into account, which causes the huge loss of legitimate flows; considering each router could contribute a few filters, the other extreme scheme pushes the filtering location back into each attack source so as to obtain ample filters, but this may incur the severe network transmission delay due to the abused filtering routers. Therefore, in this paper, we propose a scalable filter-based packet filtering scheme to balance the number of filtering routers and the available filters. Through emulating DoS scenarios based on the synthetic and real-world Internet topologies and further implementing the various filter-based packet filtering schemes on them, the results show that our scheme just uses fewer filtering routers to cut off all attack flows while minimizing the loss of legitimate flows.
引用
收藏
页码:163 / 177
页数:15
相关论文
共 50 条
  • [31] A Control Bandwidth Optimized Active Damping Scheme for LC and LCL Filter-Based Converters
    Guo, Wenyong
    Chen, Tianxiang
    Huang, Alex Q. Q.
    IEEE ACCESS, 2023, 11 : 34286 - 34296
  • [32] A Filter-Based Controller for a Buck Converter
    Mohebbi, Mohammad
    McIntyre, Michael L.
    Latham, Joseph
    Rivera, Pablo
    2017 IEEE 18TH WORKSHOP ON CONTROL AND MODELING FOR POWER ELECTRONICS (COMPEL), 2017,
  • [33] Filter-Based Fading Channel Modeling
    Alimohammad, Amirhossein
    Fard, Saeed Fouladi
    Cockburn, Bruce F.
    MODELLING AND SIMULATION IN ENGINEERING, 2012, 2012
  • [34] Threshold-based filtering buffer management scheme in a shared buffer packet switch
    Yang, Jui-Pin
    Liang, Ming-Cheng
    Chu, Yuan-Sun
    2003, Korean Institute of Communications and Information Sciences (05)
  • [35] Threshold-based filtering buffer management scheme in a shared buffer packet switch
    Yang, JP
    Liang, MC
    Chu, YS
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2003, 5 (01) : 82 - 89
  • [36] Fast Filter-Based Boolean Matchers
    Yu, Chaofan
    Wang, Lingli
    Zhang, Chun
    Hu, Yu
    He, Lei
    IEEE EMBEDDED SYSTEMS LETTERS, 2013, 5 (04) : 65 - 68
  • [37] Optimal filter-based detection of microcalcifications
    Gulsrud, TO
    Husoy, JH
    IEEE TRANSACTIONS ON BIOMEDICAL ENGINEERING, 2001, 48 (11) : 1272 - 1281
  • [38] Discrete FIR filter-based Control
    Cortes-Romero, John
    Gomez-Leon, Brian
    Sira-Ramirez, Hebertt
    ISA TRANSACTIONS, 2025, 157 : 591 - 602
  • [39] Washout Filter-Based Power Sharing
    Yazdanian, Mehrdad
    Mehrizi-Sani, Ali
    IEEE TRANSACTIONS ON SMART GRID, 2016, 7 (02) : 967 - 968
  • [40] A Filter-Based Format Conversion Approach
    Jeon, Gwanggil
    Kang, SeokHoon
    Lee, Young-Sup
    CONVERGENCE AND HYBRID INFORMATION TECHNOLOGY, 2012, 310 : 559 - 565