SAFE: a Scalable Filter-Based Packet Filtering Scheme

被引:0
|
作者
Lu Ning [1 ,2 ,3 ]
Hu Wenhao [1 ]
机构
[1] Northeastern Univ, Coll Informat Sci & Engn, Shenyang 110819, Liaoning, Peoples R China
[2] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100000, Peoples R China
[3] Nanjing Univ Informat Sci & Technol, Nanjing 210044, Jiangsu, Peoples R China
关键词
internet security; DoS attacks; filtering scheme; DDOS;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Denial-of-Service (DoS) attacks have become the mainstream threat to the Internet service availability. The filter-based packet filtering is a key technology to defend against such attacks. Relying on the filtering location, the proposed schemes can be grouped into Victim-end Filtering and Source-end Filtering. The first scheme uses a single filtering router to block the attack flows near the victim, but does not take the factor that the filters are scarce resource into account, which causes the huge loss of legitimate flows; considering each router could contribute a few filters, the other extreme scheme pushes the filtering location back into each attack source so as to obtain ample filters, but this may incur the severe network transmission delay due to the abused filtering routers. Therefore, in this paper, we propose a scalable filter-based packet filtering scheme to balance the number of filtering routers and the available filters. Through emulating DoS scenarios based on the synthetic and real-world Internet topologies and further implementing the various filter-based packet filtering schemes on them, the results show that our scheme just uses fewer filtering routers to cut off all attack flows while minimizing the loss of legitimate flows.
引用
收藏
页码:163 / 177
页数:15
相关论文
共 50 条
  • [41] Filter-Based Wilkinson Power Divider
    Chau, Wei-Ming
    Hsu, Ko-Wen
    Tu, Wen-Hua
    IEEE MICROWAVE AND WIRELESS COMPONENTS LETTERS, 2014, 24 (04) : 239 - 241
  • [42] Filter-based unsteady RANS computations
    Johansen, ST
    Wu, JY
    Shyy, W
    INTERNATIONAL JOURNAL OF HEAT AND FLUID FLOW, 2004, 25 (01) : 10 - 21
  • [43] A Kalman filter-based automatic rotor dynamic balancing scheme for electric motor mass production
    Tseng, CY
    Shih, TW
    Lin, JT
    PROGRESS ON ADVANCED MANUFACTURE FOR MICRO/NANO TECHNOLOGY 2005, PT 1 AND 2, 2006, 505-507 : 997 - 1002
  • [44] Orthogonal Filter-Based Networks for Learning
    Sienko, Wieslaw
    Citko, Wieslaw
    ADVANCES IN COGNITIVE NEURODYNAMICS, PROCEEDINGS, 2008, : 873 - +
  • [45] Particle Filter-Based Passive Islanding Detection Scheme for Renewable Energy Penetrated Distribution Systems
    Tahir Chauhdary, Sohaib
    Mumtaz, Faisal
    Ahmed Sher, Hadeed
    Almutairi, Sulaiman Z.
    Aljumah, Ali S.
    Faisal Muratza, Ali
    Alqahtani, Mohammed H.
    IEEE ACCESS, 2024, 12 : 147501 - 147515
  • [46] Robust and Scalable Deterministic Packet Marking Scheme for IP Traceback
    Lin, Iven
    Lee, Tsern-Huei
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [47] A scheme to construct scalable packet switching fabrics of Torus Topology
    Wang, Hong
    Xu, Du
    Liao, Dan
    Li, Lemin
    2007 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS PROCEEDINGS, VOLS 1 AND 2: VOL 1: COMMUNICATION THEORY AND SYSTEMS; VOL 2: SIGNAL PROCESSING, COMPUTATIONAL INTELLIGENCE, CIRCUITS AND SYSTEMS, 2007, : 496 - +
  • [48] Washout Filter-Based Decentralized Control Scheme for Economic Operation of Islanded AC/DC Microgrids
    Zheng, Shunwei
    Zhang, Jun
    Liao, Kai
    Yang, Jianwei
    Xu, Yangjun
    PROCEEDINGS OF THE 15TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (ICIEA 2020), 2020, : 437 - 442
  • [49] KALP: A Kalman filter-based adaptive clock method with low-pass prefiltering for packet networks use
    Kim, KS
    Lee, BG
    IEEE TRANSACTIONS ON COMMUNICATIONS, 2000, 48 (07) : 1217 - 1225
  • [50] A New Filter Scheme for the Filtering of Fault Currents
    Yu, Chi-Shan
    2009 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY, VOLS 1-3, 2009, : 720 - 725