首页> 外文OA文献 >PAS: A Packet Accounting System to Limit the Effects of DoS DDoS
【2h】

PAS: A Packet Accounting System to Limit the Effects of DoS DDoS

机译:pas:限制Dos和DDos影响的分组计费系统

摘要

Denial of Service (DoS) and Distributed DoS (DDoS) attacks have proven to be increasing threats to our digital world. There aremany approaches for trying to deal with these threats. With significant overhead and computational complexity, some of these methods can limit the effects of DoS and DDoS in some cases. However they cannot handle scenarios such as when both end hosts collude or when the route of the packets change. Here we present a noble packet accounting system (PAS) to deal with DoS and DDoS. The main idea of PAS is that if every packet is accounted or paid for, then the DoS and DDoS problem reduces into a congestion control and fairness problem. It can then be dealt with by finding better routes or adjusting the sending rates. Hence PAS can also serve as a congestion control and routing scheme with packet pricing. Our scheme can be implemented in the current Internet with few additional features to the current network infrastructure. Preliminary numerical NS2 simulation results show that our scheme can outperform TVA, a well known DoS mitigation approach. We are working on real implementation of PAS prototype.
机译:事实证明,拒绝服务(DoS)和分布式DoS(DDoS)攻击正日益威胁着我们的数字世界。有很多方法可以应对这些威胁。由于开销巨大且计算复杂,某些方法可能会限制DoS和DDoS的效果。但是,它们无法处理以下情况,例如当两个终端主机合谋或数据包的路由更改时。在这里,我们提出了一种贵族分组计费系统(PAS),用于处理DoS和DDoS。 PAS的主要思想是,如果对每个数据包都进行了结算或付款,则DoS和DDoS问题将减少为拥塞控制和公平性问题。然后,可以通过找到更好的路线或调整发送速率来处理它。因此,PAS还可以用作数据包定价的拥塞控制和路由方案。我们的方案可以在当前的Internet中实现,而对当前的网络基础结构几乎没有附加功能。初步的NS2数值模拟结果表明,我们的方案可以胜过众所周知的DoS缓解方法TVA。我们正在研究PAS原型的实际实现。

著录项

  • 作者单位
  • 年度 2010
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号