【24h】

Design of Secure Diffserv Ingress Edge Routers

机译:安全DiffServ入口边缘路由器的设计

获取原文

摘要

Classical Differentiated Service (DiffServ) routers have not considered the security problem in their designs, generally, they have no ability to countering Denial of Service (DoS ) attacks because of their simple system structures. DoS attacks against DiffServ clients are more targeted and require less attack bandwidth than current attacks for classical DiffServ routers due to the per-client and perclass bandwidth limitations, since they must be imposed to ensure QoS guarantees. To solve the problem, in this paper, we present the design of new ingress DiffServ edge router(IDER) for defeating DoS attacks on DiffServ clients. The classifier and access control model of ingress DiffServ edge routers(IDERs) secure the Quality of Service (QoS) by policing traffics and limiting the data rate and access number of traffics, and distinguish the traffics with higher priorities from malicious traffics. The algorithms of secure TCP AQM and UDP AQM are derived from two fluid models. The network behaviors of proposed secure IDERs have been simulated by several to two fluid models with the traffic policing.
机译:经典差异化服务(DiffServ)路由器在其设计中没有考虑安全问题,通常,由于系统结构简单,它们没有能够抵消拒绝服务(DOS)攻击。对DiffServ客户端的DOS攻击更具针对性,并且由于每个客户端和Perclass带宽限制,因此需要较少的攻击带宽,因为必须施加它们以确保QoS保证。为了解决问题,在本文中,我们展示了新入口DiffServ边缘路由器(IDER)的设计,用于击败DiffServ客户端的DOS攻击。 Intress DiffServ边缘路由器(IDERS)的分类器和访问控制模型通过监管流量和限制数据速率和访问数量的数据速度和访问数量,并将流量与更高优先级的可恶意流行的优先级区分开来保护服务质量。安全TCP AQM和UDP AQM的算法源自两个流体模型。建议安全国内的网络行为已被几到两个流体模型模拟,具有交通警照。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号