首页> 外文会议>ICISCI 2011;International conference on information systems and computational intelligence >Towards Congestion Control in Mobile Devices by Combating TCP Based Attacks
【24h】

Towards Congestion Control in Mobile Devices by Combating TCP Based Attacks

机译:通过对抗基于TCP的攻击来实现移动设备的拥塞控制

获取原文

摘要

There are several existing solutions on congestion control in low bandwidth mobile devices and among them is the packet drop policy. This paper proposes a different approach to address the same by combating the TCP based attacks. The firewall verifys the validity of a client before being allowed to connect to the network. A client sends a SYN request to the TCP server through the firewall, the firewall sends a SYN/ACK with a wrong sequence number to the client. The client sends an RST which the firewall checks to see whether their sequence numbers match before forwarding the SYN request to the server. The server returns a SYN/ACK to the client through the firewall. An ACK from the client is held by the firewall awaiting a retransmission of the same. The firewall then checks the sequence numbers of the SYN, RST and the two ACKs. If they match, the client is allowed to connect to the network otherwise the firewall uses the suggested Drop Invalid Mechanism (DIM) to ask the server to release all the resources associated with this client. The firewall uses a timer in waiting for the RST and the second ACK and if the client exceeds a set time, it is proved invalid and hence dropped before a connection is established. The results from the tools used to analyse this paper shows that the delay in performance caused by this verification only takes micro seconds which cannot be compared to the benefits of reducing congestion in the network.
机译:在低带宽移动设备中,有几种关于拥塞控制的现有解决方案,其中之一就是丢包策略。本文提出了一种通过对抗基于TCP的攻击来解决相同问题的不同方法。防火墙在允许客户端连接到网络之前会先验证其有效性。客户端通过防火墙向TCP服务器发送SYN请求,防火墙向客户端发送序列号错误的SYN / ACK。客户端发送RST,防火墙在将SYN请求转发到服务器之前检查防火墙的序列号是否匹配。服务器通过防火墙向客户端返回SYN / ACK。客户端会保留来自客户端的ACK,以等待其重新传输。然后,防火墙检查SYN,RST和两个ACK的序列号。如果它们匹配,则允许客户端连接到网络,否则防火墙使用建议的丢弃无效机制(DIM)来请求服务器释放与此客户端关联的所有资源。防火墙使用计时器等待RST和第二个ACK,如果客户端超过了设置的时间,则证明该客户端无效,因此在建立连接之前被丢弃。用于分析本文的工具的结果表明,此验证导致的性能延迟仅需数微秒,这与减少网络拥塞的好处无法相比。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号