Mitigating congestion based DoS attacks with an enhanced AQM technique
نویسندگان
چکیده
Denial of Service (DoS) attacks are currently one of the biggest risks any organization connected to the Internet can face. Hence, the congestion handling techniques at the edge router(s), such as Active Queue Management (AQM) schemes must take into account such attacks. Ideally, an AQM scheme should (a) ensure that each network flow gets its fair share of bandwidth, and (b) identify attack flows so that corrective actions (e.g. drop flooding traffic) can be explicitly taken against them to further mitigate the DoS attacks. This paper presents a proof-of-concept work on devising such an AQM scheme, which we name Deterministic Fair Sharing (DFS). Most of the existing AQM schemes do not achieve the above goals or have significant room for improvement. DFS uses the concept of weighted fair share (wfs) that allows it to dynamically self-adjust the router buffer usage based on the current level of congestion, while aiding in identifying malicious flows. By using multiple data structures (a comprehensive repository and a cache) for keeping state of legitimate and malicious flows, DFS is able to optimize its runtime performance (e.g. higher bandwidth flows being handled by the cache). We demonstrate the performance advantage of DFS via extensive simulation while comparing against other existing AQM techniques. 2014 Elsevier B.V. All rights reserved.
منابع مشابه
The Pennsylvania State University The Graduate School College of Engineering NETWORK QUEUE MANAGEMENT AND CONGESTION CONTROL IN INTERNET AND WIRELESS NETWORKS
Rapid development of telecommunication technologies and the ever growing network users demands have made network congestion a prominent problem in today’s Internet. Congestion not only brings significant performance degradation to the network, but also hurts the Quality-of-Service (QoS) that the users receive and even raises up some security concerns such as Denial-of-Service (DoS) attacks. The...
متن کاملP-CHOKe: A Piggybacking-CHOKe AQM Congestion Control Method
Abstract— The Active Queue Management (AQM) is a technique that consists of ECN (Explicit Congestion notifications) in internet routers. Congestion is an important issue which researcher focuses on in the TCP network environment. AQM is a router – based mechanism for early detection of congestion inside the network. This paper provides an analysis of congestion metric with flow information in q...
متن کاملLow Rate Denial of Service (LDoS) attack – A Survey
Denial Of service (DoS) attacks has become a major problem to intranet and Internet services. DoS attacks can be detected and eliminated using existing efficient Active Queue Management (AQM) schemes like RED. A new kind of DoS attacks have become more common in today’s Transmission control protocol (TCP) services, i.e., Low Rate Denial of Service (LDoS) attacks. LDoS attacks will degrade the p...
متن کاملFuzzy Active Queue Management for Congestion Control in Wireless Ad-Hoc
Mobile ad-hoc network is a network without infrastructure where every node has its own protocols and services for powerful cooperation in the network. Every node also has the ability to handle the congestion in its queues during traffic overflow. Traditionally, this was done through Drop-Tail policy where the node drops the incoming packets to its queues during overflow condition. Many studies ...
متن کاملIntelligent Reasoning Approach for Active Queue Management in Wireless Ad Hoc Networks
Mobile ad hoc network is a network without infrastructure where every node has its own protocols and services for powerful cooperation in the network. Every node also has the ability to handle the congestion in its queues during traffic overflow. Traditionally, this was done through DropTail policy where the node drops the incoming packets to its queues during overflow condition. Many studies s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Computer Communications
دوره 56 شماره
صفحات -
تاریخ انتشار 2015