Ingress Filtering at Edge Network to Protect Vpn Service from Dos Attack

نویسندگان

  • S. Saraswathi
  • P. Yogesh
چکیده

Internet Protocol (IP) examines only the packet header to forward the packet but it does not examine the data in it. As internet is open to public, the seeking for sensitive data by the attacker has increased. It has become a necessity to protect data through the Internet. Virtual Private Network (VPN) is a popular service to logically construct private network using the existing public infrastructure. It helps in constructing a geographically dispersed LAN that can securely communicate data using the Internet as the backbone communication network. IP Security (IPSec) VPN provides confidentiality, integrity and availability through tunnelling and encryption. IPSec protocol provides various security features but it does not provide any protection against Denial of Service (DoS) attack. DoS attacks to VPN represent a serious threat to enterprises operating over the Internet. It also hinders the services provided by the service providers. Malicious traffic enters into the Internet only through the edge network. To provide an uninterrupted VPN service, a protection mechanism is to be added at the edge network. This paper discusses such protection mechanisms based on filtering and cryptographic technique.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Mitigating Strategy to Shield the VPN Service from DoS Attack

The exponential growth of internet and drastic enhancement in telecommunication has made the Internet a part of every aspect in the world. Internet is now the heart of the day to day business dealings throughout the world. This has increased the seeking for sensitive data by the attacker. This in turn increased the necessity to protect data through the Internet. Virtual Private Network (VPN) is...

متن کامل

On IP-VPN Fairness Control Mechanism using AIMD Window Flow Control

In recent years, IP-VPN (IP-based Virtual Private Network) that realizes a virtual dedicated line on the existing IP network has been capturing the spotlight. However, in the conventional IP-VPN, there is a problem that the fairness among IP-VPN customers is not guaranteed. In this paper, we therefore propose an IP-VPN fairness control mechanism called I2VFC (Interand Intra-VPN Fairness Control...

متن کامل

CenterTrack: An IP Overlay Network for Tracking DoS Floods

Finding the source of forged Internet Protocol (IP) datagrams in a large, high-speed network is difficult due to the design of the IP protocol and the lack of sufficient capability in most high-speed, highcapacity router implementations. Typically, not enough of the routers in such a network are capable of performing the packet forwarding diagnostics required for this. As a result, tracking-dow...

متن کامل

A security framework for protecting traffic between collaborative domains

In this paper, we propose a novel Secure Name Service (SNS) framework for enhancing the service availability between collaborative domains (e.g., extranets). The key idea is to enforce packet authentication through resource virtualization and utilize dynamic name binding to protect servers from unauthorized accesses, denial of service (DOS) and other attacks. Different from traditional static n...

متن کامل

Engineering Task Force ( IETF ) H . Jeng

With BGP/MPLS Virtual Private Networks (VPNs), providing any-to-any connectivity among sites of a given VPN would require each Provider Edge (PE) router connected to one or more of these sites to hold all the routes of that VPN. The approach described in this document allows the VPN service provider to reduce the number of PE routers that have to maintain all these routes by requiring only a su...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012