Programming routers to improve network security
نویسندگان
چکیده
Denial of Service (DoS ) attacks represent, in today’s Internet, one of the most complex issues to address. In this paper we present a novel approach to deal with Distributed DoS (DDoS ) attacks in the Internet. We propose a model for an Active Security System, comprising a number of components that actively cooperate in order to effectively react to a wide range of attacks. Functional to our approach is a network signaling protocol, named Active Security Protocol , which allows a set of active routers to interact in order to isolate the sources of a DDoS attack even in the case of address spoofing. Deployment and tuning of the Active Security System are ideally suited to a Programmable Network environment. 1 Denial of Service: attacks and protection Denial of Service attacks aim at compromising a distributed system’s availability by consuming its resources as much as possible [1]. Several attack techniques have been conceived and exploited over the Internet in the past few years. Among them, Distributed DoS (DDoS) attacks represent the most complex case to deal with. Two are the key actions that must be performed when recognizing and reacting to DoS attacks: Intrusion Detection and Traceback. An Intrusion Detection System (IDS) [2] is an entity devoted to the detection of both non-authorized uses and misuses of a system. Recently, lots of efforts have been devoted to the definition and introduction of IDS components inside network routers, even within the IETF community. IP Traceback is concerned with detecting the source(s) of a DoS attack. The most complex issue it has to face is related to the fact that the attackers often use spoofed IP addresses, thus preventing effective detection via a simple analysis of the IP header of the received packets. As a countermeasure to this attack strategy, packet marking techniques are often employed.
منابع مشابه
طراحی شبکه ارتباطی بیسیم قابل اطمینان برای شبکه هوشمند برق با استفاده از برنامهریزی خطی
The challenging characteristics of Smart Grid such as the vast size of covered area and tight requirements of reliability (higher than 0.98) and delay (in terms of second and millisecond) impede the procedure of communication network designing. This paper investigates the problem of network designing subject to the reliability constraint. The main contribution is dividing the problem into two s...
متن کاملSecurity Constrained Unit Commitment in the Simultaneous Presence of Demand Response Sources and Electric Vehicles
Due to the ever-growing load, especially peak load, the increase in the capacity of plants is inevitable for the response to this growth. Peak load causes increases in customer costs and vast investments in generating and transmission parts. Therefore, restructuring in the electrical industry, competition in the electrical market and Demand Response Programs (DRPs) are of special importance in ...
متن کاملNon-Blocking Routers Design Based on West First Routing Algorithm & MZI Switches for Photonic NoC
For the first time, the 4- and 5-port optical routers are designed by using the West First routing algorithm for use in optical network on chip. The use of the WF algorithm has made the designed routers to provide non-blocking routing in photonic network on chip. These routers not only are based on high speed Mach-Zehnder switches(Which have a higher bandwidth and more thermal tolerance than mi...
متن کاملNon-Blocking Routers Design Based on West First Routing Algorithm & MZI Switches for Photonic NoC
For the first time, the 4- and 5-port optical routers are designed by using the West First routing algorithm for use in optical network on chip. The use of the WF algorithm has made the designed routers to provide non-blocking routing in photonic network on chip. These routers not only are based on high speed Mach-Zehnder switches(Which have a higher bandwidth and more thermal tolerance than mi...
متن کاملPlanning and Operation of the Active and Reactive sources Constrained to Voltage Security in the Reconfigurable Smart Distribution Network
One of the most important objectives of smart distribution networks (SDNs) is to achieve a secure and reliable network. This can be realized by optimal operation in the presence of active power sources such as the distributed generations (DGs), reactive power sources such as switched capacitor bank (SCB), active loads such as the demand response program (DRP), and various network management str...
متن کاملController Placement in Software Defined Network using Iterated Local Search
Software defined network is a new computer network architecture who separates controller and data layer in network devices such as switches and routers. By the emerge of software defined networks, a class of location problems, called controller placement problem, has attracted much more research attention. The task in the problem is to simultaneously find optimal number and location of controll...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2001