【24h】

Interest Flow Control Method Based on User Reputation and Content Name Prefixes in Named Data Networking

机译:命名数据网络中基于用户信誉和内容名称前缀的兴趣流控制方法

获取原文

摘要

Interest Flooding Attack (IFA) is a big problem in Named Data Networking (NDN). In IFA, an attacker repeats sending an excessive number of Interest packets requesting non-existing contents within short time in order to overload the network. It causes service disruptions for normal users. Pushback mechanism is a representative countermeasure against IFA in NDN. However, the mechanism also limits Interests from normal users, because it controls the flow in all routers affected by IFA. In addition, they assume only simple constant attack model in NDN. As a result, the data acquisition of normal users decreases. In this paper, we propose an Interest flow control method based on user reputation and content name prefixes in Named Data Networking, called ICRP. In ICRP, an edge router limits only Interests from malicious users who are attackers by user reputation. Here, reputation is the value that means the transmission degree of Interest requiring existing contents. As the reputation reflects the past behavior of each user, ICRP considers malicious users change their behavior. Furthermore, the edge router reduces the number of malicious Interests by content name prefixes. The edge router makes a blacklist of non-existing name prefixes requested by the detected malicious users. We evaluate ICRP by simulation. We confirm that ICRP can suppress the limitation to Interests from normal users. Furthermore, ICRP can alleviate the fluctuation the data acquisition rate of normal users even if malicious users change their behavior.
机译:兴趣泛洪攻击(IFA)是命名数据网络(NDN)中的一个大问题。在IFA中,攻击者会在短时间内重复发送过多的兴趣数据包,以请求不存在的内容,从而使网络超载。它会导致普通用户的服务中断。推回机制是NDN中针对IFA的代表性对策。但是,该机制还限制了普通用户的兴趣,因为它可以控制受IFA影响的所有路由器中的流量。此外,它们仅假设NDN中的简单恒定攻击模型。结果,普通用户的数据获取减少。在本文中,我们提出了一种基于命名数据​​网络中用户信誉和内容名称前缀的兴趣流控制方法,称为ICRP。在ICRP中,边缘路由器仅通过用户信誉来限制攻击者的恶意用户的兴趣。在此,信誉是表示需要现有内容的兴趣的传送程度的值。由于信誉反映了每个用户的过去行为,因此ICRP认为恶意用户会更改其行为。此外,边缘路由器通过内容名称前缀减少了恶意内容的数量。边缘路由器将检测到的恶意用户请求的不存在的名称前缀列入黑名单。我们通过仿真评估ICRP。我们确认ICRP可以抑制普通用户对兴趣的限制。此外,即使恶意用户改变了行为,ICRP也可以缓解正常用户的数据获取率的波动。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号