首页> 外文会议>International Conference on Computer Communications and Networks >On design and evaluation of 'intention-driven' ICMP traceback
【24h】

On design and evaluation of 'intention-driven' ICMP traceback

机译:关于“意向”ICMP回溯的设计与评估

获取原文

摘要

Since late 1999, DDoS (Distributed Denial of Service) [1,2,3] attack has drawn many attentions from both research and industry communities. Many potential solutions (e.g., ingress filtering [6,7], packet marking [5,8,9,10,11] or tracing [4], and aggregate-based congestion control or rate limiting) have been proposed to handle this network bandwidth consumption attack. Among them, "ICMP traceback (iTrace)" is currently being considered as an industry standard by IETF (Internet Engineering Task Force). While the idea of iTrace is very clever, efficient, reasonably secure and practical, it suffers a serious statistic problem such that the chance for "useful" and "valuable" iTrace messages can be extremely small against various types of DDoS attacks. This implies that most of the network resources spent on generating and utilizing iTrace messages will be wasted. Therefore, we propose a simple enhancement called "Intention-Driven" iTrace, which conceptually introduces an extra bit in the routing and forwarding process. With the new "intention-bit", it is shown that, through our simulation study, the performance of iTrace improves dramatically. This work has been proposed to IETF's ICMP Trace-Back working group.
机译:自1999年底,DDoS攻击(分布式拒绝服务)[1,2,3]攻击已经引起研究和行业团体的许多关注。许多潜在的解决方案(例如,入口过滤[6,7],数据包标记[5,8,9,10,11]或追踪[4],和聚合的基于拥塞控制或速率限制)已经提出来处理这个网络带宽消耗攻击。其中,“ICMP回溯(iTrace)”目前正在考虑由IETF(互联网工程任务组)的行业标准。虽然iTrace的想法很聪明,高效,合理的安全和实用,它遭受了严重的问题,统计这样的“有用”和“有价值” iTrace消息的机会可以针对不同类型的DDoS攻击非常小。这意味着,大部分花在生成和使用iTrace消息中的网络资源将被浪费。因此,我们提出了一个简单的增强所谓的“意向驱动” iTrace,其概念引入了额外的比特的路由和转发的过程。随着新的“意向位”,它表明,通过我们的模拟研究,iTrace的性能显着提高。这项工作提出了IETF的ICMP追溯工作组。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号