【24h】

Cache Control Method Mitigating Packet Concentration of Router Caused by Interest Flooding Attack

机译:减轻兴趣洪泛攻击引起的路由器数据包集中的缓存控制方法

获取原文
获取原文并翻译 | 示例

摘要

Interest Flooding Attack (IFA) is one of the problems in Named Data Networking (NDN). In IFA, attackers send an excessive number of requests for non-existing contents, so it makes PIT overflow. It prevents normal users from retrieving Data packets. Pushback mechanism is a representative countermeasure against IFA in NDN. Pushback, however, limits Interest packets at routers near the server, so it also limits normal Interest packets. ICRP is another countermeasure against IFA. In ICRP, edge routers detect attackers and limit Interest packets from attackers. ICRP does not limit normal Interest packets, but each router needs to know the overall structure of the network to confirm whether it is an edge router by itself. In this paper, we propose an Interest flow balancing method focused on the number of requests on Named Data Networking, called IFBN. IFBN aims at decreasing the number of records in PIT from attackers and recovering the number of Data packets that normal users can retrieve. First, routers calculate reputation values for each interface. The reputation value is a proportion of the number of retrieved Data packets to the number of Interest packets forwarded for each interface. In addition to reputation values, routers refer to PIT and check the number of information from each interface. The router concludes that the interface that uses most capacity of PIT is forwarded attack Interest packets. The router does not record information of Interest packets from affected interface in PIT. Therefore, IFBN does not record only information of attack Interest packets without limiting normal Interest packets. We evaluate IFBN by simulation, and confirm IFBN can limit only attack Interest packets.
机译:兴趣泛洪攻击(IFA)是命名数据网络(NDN)中的问题之一。在IFA中,攻击者发送了过多的不存在内容请求,因此使PIT溢出。它阻止普通用户检索数据包。推回机制是NDN中针对IFA的代表性对策。但是,推回限制了服务器附近路由器上的兴趣数据包,因此也限制了正常的兴趣数据包。 ICRP是针对IFA的另一对策。在ICRP中,边缘路由器检测攻击者并限制攻击者的兴趣数据包。 ICRP不会限制正常的兴趣数据包,但是每个路由器都需要了解网络的整体结构,以确认它本身是否是边缘路由器。在本文中,我们提出了一种兴趣流均衡方法,该方法关注于命名数据​​网络上的请求数,称为IFBN。 IFBN旨在减少攻击者在PIT中的记录数量,并恢复普通用户可以检索的数据包数量。首先,路由器计算每个接口的信誉值。信誉值是检索到的数据包数量与每个接口转发的兴趣包数量的比例。除了信誉值,路由器还参考PIT并检查每个接口的信息数量。路由器得出的结论是,使用最多PIT容量的接口已转发攻击兴趣数据包。路由器不会在PIT中记录来自受影响接口的兴趣数据包信息。因此,IFBN不会仅记录攻击兴趣数据包的信息,而不会限制正常的兴趣数据包。我们通过仿真评估IFBN,并确认IFBN只能限制攻击兴趣数据包。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号