Mitigating congestion based DoS attacks with an enhanced AQM technique

نویسندگان

  • Harkeerat Singh Bedi
  • Sankardas Roy
  • Sajjan G. Shiva
چکیده

Denial of Service (DoS) attacks are currently one of the biggest risks any organization connected to the Internet can face. Hence, the congestion handling techniques at the edge router(s), such as Active Queue Management (AQM) schemes must take into account such attacks. Ideally, an AQM scheme should (a) ensure that each network flow gets its fair share of bandwidth, and (b) identify attack flows so that corrective actions (e.g. drop flooding traffic) can be explicitly taken against them to further mitigate the DoS attacks. This paper presents a proof-of-concept work on devising such an AQM scheme, which we name Deterministic Fair Sharing (DFS). Most of the existing AQM schemes do not achieve the above goals or have significant room for improvement. DFS uses the concept of weighted fair share (wfs) that allows it to dynamically self-adjust the router buffer usage based on the current level of congestion, while aiding in identifying malicious flows. By using multiple data structures (a comprehensive repository and a cache) for keeping state of legitimate and malicious flows, DFS is able to optimize its runtime performance (e.g. higher bandwidth flows being handled by the cache). We demonstrate the performance advantage of DFS via extensive simulation while comparing against other existing AQM techniques. 2014 Elsevier B.V. All rights reserved.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The Pennsylvania State University The Graduate School College of Engineering NETWORK QUEUE MANAGEMENT AND CONGESTION CONTROL IN INTERNET AND WIRELESS NETWORKS

Rapid development of telecommunication technologies and the ever growing network users demands have made network congestion a prominent problem in today’s Internet. Congestion not only brings significant performance degradation to the network, but also hurts the Quality-of-Service (QoS) that the users receive and even raises up some security concerns such as Denial-of-Service (DoS) attacks. The...

متن کامل

P-CHOKe: A Piggybacking-CHOKe AQM Congestion Control Method

Abstract— The Active Queue Management (AQM) is a technique that consists of ECN (Explicit Congestion notifications) in internet routers. Congestion is an important issue which researcher focuses on in the TCP network environment. AQM is a router – based mechanism for early detection of congestion inside the network. This paper provides an analysis of congestion metric with flow information in q...

متن کامل

Low Rate Denial of Service (LDoS) attack – A Survey

Denial Of service (DoS) attacks has become a major problem to intranet and Internet services. DoS attacks can be detected and eliminated using existing efficient Active Queue Management (AQM) schemes like RED. A new kind of DoS attacks have become more common in today’s Transmission control protocol (TCP) services, i.e., Low Rate Denial of Service (LDoS) attacks. LDoS attacks will degrade the p...

متن کامل

Fuzzy Active Queue Management for Congestion Control in Wireless Ad-Hoc

Mobile ad-hoc network is a network without infrastructure where every node has its own protocols and services for powerful cooperation in the network. Every node also has the ability to handle the congestion in its queues during traffic overflow. Traditionally, this was done through Drop-Tail policy where the node drops the incoming packets to its queues during overflow condition. Many studies ...

متن کامل

Intelligent Reasoning Approach for Active Queue Management in Wireless Ad Hoc Networks

Mobile ad hoc network is a network without infrastructure where every node has its own protocols and services for powerful cooperation in the network. Every node also has the ability to handle the congestion in its queues during traffic overflow. Traditionally, this was done through DropTail policy where the node drops the incoming packets to its queues during overflow condition. Many studies s...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Computer Communications

دوره 56  شماره 

صفحات  -

تاریخ انتشار 2015