首页> 外文期刊>Journal of network and computer applications >Efficient DDoS attacks mitigation for stateful forwarding in Internet of Things
【24h】

Efficient DDoS attacks mitigation for stateful forwarding in Internet of Things

机译:高效的DDoS攻击缓解措施可在物联网中进行有状态转发

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Stateful forwarding plane is fully considered as a novel forwarding paradigm, which is proven to be beneficial to delivery efficiency and resilient to certain types of attacks. However, this fresh attempt also introduces "varietal" Denial-of-Service attack due to complicated forwarding state operations, which may cause long-term memory exhaustion of forwarding nodes, especially for resource-limited IoT nodes. This new distributed exhaustion attack is extremely hidden and there is currently no effective defense against it. In this paper, we first establish a game model to analyze the attack benefit between attacker and defender. To further make the defender obtain more utility, it is significative to make the defender manage expired state-entries during stateful forwarding. To this end, we propose an enhanced distributed low-rate attack mitigating (eDLAM) mechanism. Particularly, eDLAM maintains a lightweight malicious request table (MRT), which is very small, to offload burden of practical forwarding state table. When a packet request is matched in MRT, it will be marked and dropped directly without any impact on forwarding state table. Based on this, eDLAM adopts an optimal threshold update method for MRT to achieve a maximum defender utility. We evaluate the eDLAM performance in terms of false negatives rate (FNR) and false positives rate (FPR). Extensive experimental results show that eDLAM can reduce FNR by 10.5% and FPR by 44% on average compared with state-of-the-art mechanisms.
机译:有状态的转发平面被完全认为是一种新颖的转发范式,已被证明对提高传送效率和抵御某些类型的攻击具有帮助。但是,由于复杂的转发状态操作,这种新尝试还引入了“各种”拒绝服务攻击,这可能导致转发节点的长期内存耗尽,尤其是对于资源受限的IoT节点。这种新的分布式用尽攻击非常隐蔽,目前还没有有效的防御措施。在本文中,我们首先建立了一个博弈模型来分析攻击者和防御者之间的攻击收益。为了进一步使防御者获得更多的效用,有意义的是使防御者在有状态转发期间管理过期的状态条目。为此,我们提出了一种增强的分布式低速率攻击缓解(eDLAM)机制。特别是,eDLAM维护一个非常小的轻量级恶意请求表(MRT),以减轻实际转发状态表的负担。当数据包请求在MRT中匹配时,将直接对其进行标记和丢弃,而不会影响转发状态表。基于此,eDLAM为MRT采用了最佳阈值更新方法,以实现最大的防御者效用。我们根据误报率(FNR)和误报率(FPR)评估eDLAM性能。大量的实验结果表明,与最新的机制相比,eDLAM可以平均降低FNR 10.5%和FPR 44%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号