首页> 外文会议>International Conference on Computing, Communication and Networking Technologies >Data Sequence Map Flooding in MPTCP Framework: Potential Challenges and Efficient Countermeasures
【24h】

Data Sequence Map Flooding in MPTCP Framework: Potential Challenges and Efficient Countermeasures

机译:MPTCP框架中的数据序列图泛滥:潜在的挑战和有效的对策

获取原文

摘要

Multipath Transmission Control Protocol (MPTCP) is a new protocol currently under design and standardization by the Internet Engineering Task Force (IETF). Its primary objective is to enable TCP to operate over multiple paths simultaneously. The protocol consists of a set of new signaling options that needs to be exchanged regularly between MPTCP capable endpoints through the TCP option field. Data Sequence Map (DSM) is one of the most crucial information that needs to be exchanged between the MPTCP endpoints. In this paper, we analyze the DSM exchange mechanism in MPTCP, from a security perspective, and identify potential misbehaviors by MPTCP endpoints. In particular, considering the fact that MPTCP is a stateful transport layer protocol, we explore the possibility of a new adverse scenario called Data Sequence Map flooding (DSM flooding). To the best of our knowledge, this paper for the first time describes three representative scenarios of DSM flooding: 1) DSM flooding through pure acknowledgements (ACKs), 2) DSM Flooding through map splitting and 3) Noncontiguous map splitting and flooding. DSM flooding can be performed by either of the MPTCP endpoints after establishing a MPTCP connection. We highlight the impact of DSM flooding on the other endpoint. We also propose novel countermeasures, including a map aggregation technique for the map receiving endpoint, to reduce the impact of DSM flooding in MPTCP framework.
机译:多路径传输控制协议(MPTCP)是Internet工程任务组(IETF)当前正在设计和标准化的新协议。其主要目的是使TCP同时在多个路径上运行。该协议包含一组新的信令选项,需要通过TCP选项字段在支持MPTCP的端点之间定期进行交换。数据序列图(DSM)是需要在MPTCP端点之间交换的最关键的信息之一。在本文中,我们从安全角度分析了MPTCP中的DSM交换机制,并通过MPTCP端点识别了潜在的不良行为。特别是,考虑到MPTCP是有状态传输层协议这一事实,我们探索了一种称为数据序列图泛洪(DSM泛洪)的新不利情况的可能性。据我们所知,本文首次描述了三种典型的DSM泛洪方案:1)通过纯确认(ACK)进行DSM泛洪; 2)通过地图拆分进行DSM泛洪;以及3)非连续地图拆分和泛洪。建立MPTCP连接后,可以由任一MPTCP端点执行DSM泛洪。我们重点介绍了DSM泛洪对另一个端点的影响。我们还提出了新颖的对策,包括针对地图接收端点的地图聚合技术,以减少DSTCP泛洪在MPTCP框架中的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号