首页> 外文会议>IEEE International Conference on Hot Information-Centric Networking >An Insightful Experimental Study of a Sophisticated Interest Flooding Attack in NDN
【24h】

An Insightful Experimental Study of a Sophisticated Interest Flooding Attack in NDN

机译:对NDN中复杂利息爆发的洞察力研究

获取原文

摘要

NDN (Named Data Networking), a promising next-generation architecture, puts named content in the first place of the network and is resilient to many existing DDoS attacks. However, Interest Flooding Attack (IFA), a typical NDN-specific DDoS attack, has been widely recognized as a serious threat to the development of NDN. The existing countermeasures against IFA mainly aim at the scenario that attackers send spoofed Interests at a fairly high rate and intermediate routers near the attackers can timely detect the attack by themselves. Instead, this work focuses on a more sophisticated scenario that carefully-crafted attackers send Interests at a respectively lower rate at the beginning but gradually speed up to keep the victims' PIT sizes increasing to eventually deplete the PIT resource for legitimate users. We conduct an insightful experimental study of such sophisticated IFAs on a real-world network topology and our experimental results demonstrate that the statistics of intermediate routers near the attackers change more gradually and slightly in such an attack, which makes it more difficult for an intermediate router near the attackers to detect by itself. Based on the analytical results of this study, we discuss a potential detection and countermeasure mechanism against such a sophisticated IFA in which a central controller monitors the network from a global view.
机译:NDN(命名数据组网)是一个有前途的下一代架构,将命名内容放在网络的第一个地方,并对许多现有DDOS攻击有弹性。然而,利息洪水攻击(IFA)是一个典型的NDN特定的DDOS攻击,被广泛被认为是对NDN发展的严重威胁。针对IFA的现有对策主要旨在攻击者在攻击者附近的相当高利率和中级路由器中向欺骗权兴趣的方案可以及时检测自己的攻击。相反,这项工作侧重于更复杂的情景,精心设计的攻击者在开始时分别率的速度较低,但逐渐加速,以保持受害者的​​坑大小增加,最终耗尽了合法用户的坑资源。我们对真实网络拓扑结构进行了对这种复杂的IFA的富有洞察力的实验研究,我们的实验结果表明,在这种攻击中,攻击者附近的中间路由器的统计数据更加逐渐变化,这使得中间路由器更加困难靠近攻击者来自行检测。基于本研究的分析结果,我们讨论了针对这种复杂的IFA的潜在检测和对策机制,其中中央控制器从全局视图监控网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号