Assuring Network Service with Bandwidth and Integrity Based Fairness
نویسندگان
چکیده
During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.
منابع مشابه
Assuring Network Service with Bandwidth and Integrity
During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or...
متن کاملA New Media Access Control Protocol with Quality of Service and Fairness Guarantee in Ethernet-based Passive Optical Networks
We propose a new Ethernet-based Passive Optical Network (EPON) media access control (MAC) protocol that supports quality of service (QoS) and guarantees fairness among users. For QoS support the proposed MAC protocol minimizes packet delays and delay variations for the higher priority traffic, while increases throughput efficiency for the best effort traffic by appropriate reclassification of i...
متن کاملFairly Sharing the Network for Multitier Applications in Clouds
A significant trend caused by cloud computing is to aggregate applications for sharing resources. Thus, it is necessary to provide fair resources and performance among applications, especially for the network, which is provided in the best-effort manner in current clouds. Although many studies have made efforts for provisioning fair bandwidth, they are not sufficient for network fairness. In fa...
متن کاملCluster Based Cross Layer Intelligent Service Discovery for Mobile Ad-Hoc Networks
The ability to discover services in Mobile Ad hoc Network (MANET) is a major prerequisite. Cluster basedcross layer intelligent service discovery for MANET (CBISD) is cluster based architecture, caching ofsemantic details of services and intelligent forwarding using network layer mechanisms. The cluster basedarchitecture using semantic knowledge provides scalability and accuracy. Also, the mini...
متن کاملA Fair Service Work Scheduling Approach for Differentiated Services in Optical Access Networks
We address the QoS (Quality of Services) bandwidth reservation and service work scheduling mechanism of how to fairly provide advance quality of service in polling based TDM networks like Ethernet PON (Passive Optical Networks). Unlike existing differentiated QoS supporting schemes, such as SP (Strict Priority) based DBA(Dynamic Bandwidth Allocation) or static work scheduling with min-max theor...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011