Assuring Network Service with Bandwidth and Integrity Based Fairness

نویسندگان

  • Fariba Mahboobe Khan
  • FARIBA MAHBOOBE KHAN
چکیده

During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Assuring Network Service with Bandwidth and Integrity

During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or...

متن کامل

A New Media Access Control Protocol with Quality of Service and Fairness Guarantee in Ethernet-based Passive Optical Networks

We propose a new Ethernet-based Passive Optical Network (EPON) media access control (MAC) protocol that supports quality of service (QoS) and guarantees fairness among users. For QoS support the proposed MAC protocol minimizes packet delays and delay variations for the higher priority traffic, while increases throughput efficiency for the best effort traffic by appropriate reclassification of i...

متن کامل

Fairly Sharing the Network for Multitier Applications in Clouds

A significant trend caused by cloud computing is to aggregate applications for sharing resources. Thus, it is necessary to provide fair resources and performance among applications, especially for the network, which is provided in the best-effort manner in current clouds. Although many studies have made efforts for provisioning fair bandwidth, they are not sufficient for network fairness. In fa...

متن کامل

Cluster Based Cross Layer Intelligent Service Discovery for Mobile Ad-Hoc Networks

The ability to discover services in Mobile Ad hoc Network (MANET) is a major prerequisite. Cluster basedcross layer intelligent service discovery for MANET (CBISD) is cluster based architecture, caching ofsemantic details of services and intelligent forwarding using network layer mechanisms. The cluster basedarchitecture using semantic knowledge provides scalability and accuracy. Also, the mini...

متن کامل

A Fair Service Work Scheduling Approach for Differentiated Services in Optical Access Networks

We address the QoS (Quality of Services) bandwidth reservation and service work scheduling mechanism of how to fairly provide advance quality of service in polling based TDM networks like Ethernet PON (Passive Optical Networks). Unlike existing differentiated QoS supporting schemes, such as SP (Strict Priority) based DBA(Dynamic Bandwidth Allocation) or static work scheduling with min-max theor...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011