首页> 外文OA文献 >Assuring network service with bandwidth and integrity based fairness
【2h】

Assuring network service with bandwidth and integrity based fairness

机译:基于带宽和完整性的公平性确保网络服务

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

During an Internet distributed denial-of-service (DDoS) attack, attackers pose asa superpower overloading bandwidth and services that otherwise would have beenlightly used by genuine users. These legitimate users send few packets and occasionallyback-off and fail while competing for resources. The Internet architectureprovides only modest support for verifying the true origin of a packet or intentionof a sender. This makes identification and filtering of attack traffic difficult.DDoS attacks could be limited greatly if there were a way to fairly distribute theresources among the parties despite limited origin integrity.In our work, we propose two methods for achieving fairness despite no orpartial implementation for integrity verification. Adaptive Selective Verification(ASV) provides legitimate clients service despite large but bounded attack rateswithout any integrity infrastructure. ASV can be implemented, without the cooperationof the core routers, by slight modification of the client and server applications.The other system is Integrity Based Queuing (IBQ). In this work, we expectthat integrity will not be perfect, but observe that even an imperfect implementationcan improve the effectiveness of queuing when parities with better a integritylevel are incentivized. ASV and IBQ together create a mechanism for incentives,infrastructure and independence for network service assurance.ASV is shown to be efficient in terms of bandwidth consumption using networksimulations. It differs from previously-investigated adaptive mechanismsfor bandwidth based payment by requiring very limited state on server. Our studyof IBQ includes proof of direct relationship of integrity to service, a networksimulation for comparative study, simulation with real attack traffic and securityanalysis.Our network assurance architecture provides a synergistic approach for defendingagainst DDoS attacks. With moderate infrastructure support, IBQ can be anarchitecture to provide graded source validation on the Internet. Clients that do nothave the support from the ISP, use their spare bandwidth with ASV for service.
机译:在Internet分布式拒绝服务(DDoS)攻击过程中,攻击者冒充了超能力,超载带宽和服务,否则真正的用户将无法使用它们。这些合法用户发送少量数据包,偶尔退避,并在争用资源时失败。 Internet架构仅提供适度的支持来验证包的真实来源或发送者的意图。这使得攻击流量的识别和过滤变得困难。如果尽管起源完整性受到限制,但如果有一种在各方之间公平分配资源的方法,则DDoS攻击可能会受到很大限制。验证。自适应选择性验证(ASV)可以在没有任何完整性基础结构的情况下,以很高的攻击率和有限的攻击率提供合法的客户端服务。通过略微修改客户端和服务器应用程序,可以在无需核心路由器合作的情况下实现ASV。另一个系统是基于完整性的排队(IBQ)。在这项工作中,我们期望完整性不是完美的,但是要注意,当激励具有更好完整性级别的奇偶校验时,即使是不完善的实现也可以提高排队的有效性。 ASV和IBQ共同创建了一种激励,基础设施和网络服务保证独立性的机制。通过网络仿真,ASV在带宽消耗方面被证明是有效的。它与以前研究的基于带宽的支付自适应机制不同,它要求服务器上的状态非常有限。我们对IBQ的研究包括完整性与服务的直接关系的证明,用于比较研究的网络仿真,具有实际攻击流量的仿真和安全分析。我们的网络保证体系结构提供了防御DDoS攻击的协同方法。借助适当的基础架构支持,IBQ可以成为可在Internet上提供分级源验证的体系结构。没有ISP支持的客户端,可以将其备用带宽与ASV一起使用以提供服务。

著录项

  • 作者

    Khan Fariba;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号