R. Choudhari, K. V. Arya, Mukesh Tiwari, K. Choudhary
{"title":"Performance Evaluation of SCTP-Sec: A Secure SCTP Mechanism","authors":"R. Choudhari, K. V. Arya, Mukesh Tiwari, K. Choudhary","doi":"10.1109/ICCIT.2009.277","DOIUrl":null,"url":null,"abstract":"The Stream Control Transmission Protocol (SCTP) uses a cookie mechanism to tackle the security and traditional attack scenario. Unfortunately, SCTP is not secured against redirection attacks, bombing attacks and towards verification-tag guessing attacks which lead to association-hijacking and may force the victim client to starve out of service from the server. Therefore, we propose a secure SCTP mechanism that uses an additional new SCTP chunk with cryptographic hash operation to check the integrity of the client that helps in easy detection/prevention of some traditional attacks in the SCTP. Using this, the Cookie mechanism can be minimized to clear-text.","PeriodicalId":112416,"journal":{"name":"2009 Fourth International Conference on Computer Sciences and Convergence Information Technology","volume":"47 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-11-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Fourth International Conference on Computer Sciences and Convergence Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCIT.2009.277","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The Stream Control Transmission Protocol (SCTP) uses a cookie mechanism to tackle the security and traditional attack scenario. Unfortunately, SCTP is not secured against redirection attacks, bombing attacks and towards verification-tag guessing attacks which lead to association-hijacking and may force the victim client to starve out of service from the server. Therefore, we propose a secure SCTP mechanism that uses an additional new SCTP chunk with cryptographic hash operation to check the integrity of the client that helps in easy detection/prevention of some traditional attacks in the SCTP. Using this, the Cookie mechanism can be minimized to clear-text.
SCTP (Stream Control Transmission Protocol)使用cookie机制来解决安全和传统攻击场景。不幸的是,SCTP不能抵御重定向攻击、轰炸攻击和验证标签猜测攻击,这些攻击会导致关联劫持,并可能迫使受害者客户端饿死,无法从服务器获得服务。因此,我们提出了一种安全的SCTP机制,该机制使用附加的带有加密哈希操作的新SCTP块来检查客户端的完整性,从而有助于轻松检测/预防SCTP中的一些传统攻击。使用它,Cookie机制可以最小化为明文。