首页> 外文会议>IEEE Global Communications Conference >Preventing DRDoS Attacks in 5G Networks: a New Source IP Address Validation Approach
【24h】

Preventing DRDoS Attacks in 5G Networks: a New Source IP Address Validation Approach

机译:防止DRDOS攻击5G网络:新的源IP地址验证方法

获取原文

摘要

Distributed Reflection Denial of Service (DRDoS) attack has become one of the most serious threats to Internet security. With the ongoing development of 5G, a massive number of insecure Internet of Things (IoT) devices are connected to the Internet, which brings great challenges to defend against DRDoS attacks. To overcome these challenges, we extend the User Plane Function (UPF) of 5G core network, and propose a new framework accordingly for source IP address validation, so as to suppress the source IP address spoofing behaviors of DRDoS attackers. Under this framework, the packet inspection rate (PIR), i.e., the inspection probability of each packet, is crucial to simplify the validation complexity. To unveil the optimal PIR, we establish a two-player game which models the IP address spoofing and detection behaviors. Analysis on the formulated game implies a lower bound of sufficient PIR, which may be used to set PIR in practice. Simulation results show that the proposed method can efficiently deter IP spoofing behaviors. Thereby the derived PIR could achieve low-cost and effective defense of DRDoS.
机译:分布式反思拒绝服务(DRDOS)攻击已成为互联网安全最严重的威胁之一。随着5G的持续发展,大量的不安全的东西(物联网)设备与互联网连接,这带来了彻底挑战,以防御DRDOS攻击。为了克服这些挑战,我们扩展了5G核心网络的用户平面功能(UPF),并提出了一个新的框架,以便源IP地址验证,以抑制DRDOS攻击者的源IP地址欺骗行为。在此框架下,数据包检查率(PIR),即每个数据包的检查概率,至关重要,以简化验证复杂性。要揭示最佳PIR,我们建立了一个模拟IP地址欺骗和检测行为的双人游戏。对配制游戏的分析意味着足够的PIR的下限,其可用于在实践中设置PIR。仿真结果表明,该方法可以有效地妨碍IP欺骗行为。因此,导出的PIR可以实现DRDO的低成本和有效防御。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号