首页> 外文会议>IEEE International Conference on Hot Information-Centric Networking >An Insightful Experimental Study of a Sophisticated Interest Flooding Attack in NDN
【24h】

An Insightful Experimental Study of a Sophisticated Interest Flooding Attack in NDN

机译:NDN中复杂的兴趣泛滥攻击的深入研究

获取原文

摘要

NDN (Named Data Networking), a promising next-generation architecture, puts named content in the first place of the network and is resilient to many existing DDoS attacks. However, Interest Flooding Attack (IFA), a typical NDN-specific DDoS attack, has been widely recognized as a serious threat to the development of NDN. The existing countermeasures against IFA mainly aim at the scenario that attackers send spoofed Interests at a fairly high rate and intermediate routers near the attackers can timely detect the attack by themselves. Instead, this work focuses on a more sophisticated scenario that carefully-crafted attackers send Interests at a respectively lower rate at the beginning but gradually speed up to keep the victims' PIT sizes increasing to eventually deplete the PIT resource for legitimate users. We conduct an insightful experimental study of such sophisticated IFAs on a real-world network topology and our experimental results demonstrate that the statistics of intermediate routers near the attackers change more gradually and slightly in such an attack, which makes it more difficult for an intermediate router near the attackers to detect by itself. Based on the analytical results of this study, we discuss a potential detection and countermeasure mechanism against such a sophisticated IFA in which a central controller monitors the network from a global view.
机译:NDN(命名数据网络)是一种很有前途的下一代体系结构,它将命名内容放在网络的首位,并且可以抵抗许多现有的DDoS攻击。但是,利益泛洪攻击(IFA)是一种典型的NDN特定的DDoS攻击,已被广泛认为是对NDN发展的严重威胁。现有的针对IFA的对策主要针对攻击者以很高的速率发送欺骗性利益并且攻击者附近的中间路由器可以自己及时检测到攻击的情况。取而代之的是,这项工作着眼于一个更复杂的场景,即精心设计的攻击者在开始时分别以较低的速率发送权益,但逐渐加快了速度,以使受害者的PIT规模不断增加,最终耗尽了合法用户的PIT资源。我们在现实世界的网络拓扑上对此类复杂的IFA进行了有见地的实验研究,我们的实验结果表明,在这种攻击中,攻击者附近的中间路由器的统计信息会逐渐且略有变化,这使得中间路由器更加困难靠近攻击者以自行检测。基于这项研究的分析结果,我们讨论了针对这种复杂的IFA的潜在检测和对策机制,在这种IFA中,中央控制器从全局的角度监视网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号