A Lightweight Opportunistic Tunneling

نویسنده

  • Amir Herzberg
چکیده

We present LOT, a lightweight ‘plug and play’ secure tunneling protocol deployed at network gateways. Two communicating gateways, A and B, running LOT would automatically detect each other and establish an efficient tunnel, securing communication between them. LOT tunnels allow A to discard spoofed packets that specify source addresses in B’s network and vice-versa. This helps to mitigate many attacks, including DNS poisoning, network scans and most notably (Distributed) Denial of Service (DoS). LOT tunnels provide several additional defenses against DoS attacks. Specifically, since packets received from LOT-protected networks cannot be spoofed, LOT gateways implement quotas, identifying and blocking packet floods from specific networks. Furthermore, a receiving LOT gateway (e.g., B) can send the quota assigned to each tunnel to the peer gateway (A), who can then enforce near-source quotas, reducing waste and congestion by filtering excessive traffic before it leaves the source network. Similarly, LOT tunnels facilitate near-source filtering, where the sending gateway discards packets based on filtering rules defined by the destination gateway. LOT gateways also implement an inter-gateway congestion detection mechanism, allowing sending gateways to detect when their packets get dropped before reaching the destination gateway and to perform appropriate near-source filtering to block the congesting traffic; this helps against DoS attacks on the backbone connecting the two gateways. LOT is practical: it is easy to manage (‘plug and play’, requires no coordination between gateways), deployed incrementally at edge gateways (not at hosts and core routers), and has negligible overhead in terms of bandwidth and processing, as we validate experimentally. LOT storage requirements are also modest.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Lightweight application level multicast tunnelling using mTunnel

This paper presents a system, called mTunnel, for application level tunneling of IPmulticast traffic in a lightweight manner, where the end-user is responsible for deciding which MBone-sessions and which IP-multicast groups to tunnel. mTunnel has primarily been designed for easy deployment and easy-to-manage tunneling. Information about currently tunneled sessions and control of mTunnel is prov...

متن کامل

Earnings Management and Tunneling through Related Party Transactions: Evidence from Chinese Corporate Groups*

This paper attempts to provide large sample evidence of opportunistic related party transactions in China where economic institutions, legal system and corporate structures are conducive to such dealings. We found that firms belonging to a corporate group report abnormally high levels of related party sales when they have incentives to manage earnings to avoid being delisted, or prior to issuin...

متن کامل

A Lightweight Macro-mobility Framework

This paper presents the design of a lightweight framework to provide vertical handover for macro-mobility on handheld devices. The framework is designed for mobile-controlled handover and does not require modification of the Internet infrastructure. The framework enables users to control the entire vertical handover process so handover decisions are driven by user preferences rather then ISP co...

متن کامل

Opportunistic Data Forwarding In MANETS through Proactive Source Routing

In multi hop wireless networking, Opportunistic data forwarding has drawn much attention, with most research conducted for stationary wireless networks. Opportunistic data forwarding has not been widely utilized in mobile ad hoc networks (MANETs),the reason behind this is the lack of an efficient lightweight proactive routing scheme with strong source routing capability. In this paper, proposed...

متن کامل

MODELING FLEXURAL STRENGTH OF EPS LIGHTWEIGHT CONCRETE USING REGRESSION, NEURAL NETWORK AND ANFIS

Lightweight concrete (LWC) is a kind of concrete that made of lightweight aggregates or gas bubbles. These aggregates could be natural or artificial, and expanded polystyrene (EPS) lightweight concrete is the most interesting lightweight concrete and has good mechanical properties. Bulk density of this kind of concrete is between 300-2000 kg/m3. In this paper flexural strength of EPS is modeled...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011