首页> 外文会议>IFIP WG 6.2 international conference on wired/wireless internet communications >ChoKIFA: A New Detection and Mitigation Approach Against Interest Flooding Attacks in NDN
【24h】

ChoKIFA: A New Detection and Mitigation Approach Against Interest Flooding Attacks in NDN

机译:ChoKIFA:针对NDN中的利益泛洪攻击的新检测和缓解方法

获取原文

摘要

Named-Data Networking (NDN) is a potential Future Internet Architectures which introduces a shift from the existing host-centric IP-based Internet infrastructure towards a content-oriented one. Its design, however, can be misused to introduce a new type of DoS attack, better known as Interest Flooding Attack (IFA). In IFA, an adversary issues non-satisfiable requests in the network to saturate the Pending Interest Table(s) (PIT) of NDN routers and prevent them from properly handling the legitimate traffic. Prior solutions to mitigate this problem are not highly effective, damages the legitimate traffic, and incurs high communication overhead. In this paper, we propose a novel mechanism for IFA detection and mitigation, aimed at reducing the memory consumption of the PIT by effectively reducing the malicious traffic that passes through each NDN router. In particular, our protocol exploits an effective management strategy on the PIT which differentially penalizes the malicious traffic by dropping both the inbound and already stored malicious traffic from the PIT. We implemented our proposed protocol on the open-source ndnSIM simulator and compared its effectiveness with the one achieved by the existing state-of-the-art. The results show that our proposed protocol effectively reduces the IFA damages, especially on the legitimate traffic, with improvements that go from 5% till 40% with respect to the existing state-of-the-art.
机译:命名数据网络(NDN)是一种潜在的未来Internet体系结构,它引入了从现有的以主机为中心的基于IP的Internet基础结构向面向内容的基础结构的转变。但是,其设计可能被误用于引入一种新型的DoS攻击,即众所周知的兴趣泛洪攻击(IFA)。在IFA中,攻击者会在网络中发出无法满足的请求,以使NDN路由器的未决兴趣表(PIT)饱和,并阻止它们正确处理合法流量。减轻该问题的现有解决方案不是很有效,会破坏合法流量,并导致高通信开销。在本文中,我们提出了一种用于IFA检测和缓解的新颖机制,旨在通过有效地减少流经每个NDN路由器的恶意流量来减少PIT的内存消耗。尤其是,我们的协议在PIT上采用了有效的管理策略,该策略通过从PIT中删除入站和已存储的恶意流量,从而对恶意流量进行了不同程度的惩罚。我们在开源ndnSIM模拟器上实现了我们提出的协议,并将其有效性与现有技术所实现的协议进行了比较。结果表明,我们提出的协议可有效减少IFA损害,尤其是对合法流量的损害,相对于现有技术而言,改进范围从5%到40%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号