从待处理兴趣表中解耦恶意兴趣,减轻兴趣洪水攻击

Kai Wang, Huachun Zhou, Yajuan Qin, Jia Chen, Hongke Zhang
{"title":"从待处理兴趣表中解耦恶意兴趣,减轻兴趣洪水攻击","authors":"Kai Wang, Huachun Zhou, Yajuan Qin, Jia Chen, Hongke Zhang","doi":"10.1109/GLOCOMW.2013.6825115","DOIUrl":null,"url":null,"abstract":"Named Data Networking (NDN) is a clean slate Internet paradigm that embeds some security primitives in its original design, which is being considered as one of the promising candidates for next-generation Internet architecture. However, it may suffer from some emerging threats such as Interest Flooding Attacks (IFA), which means corresponding security management mechanisms need to be designed to improve its security. In this paper, we focus on the IFA that can severely consume the memory resource for the Pending Interest Table (PIT) of each involved NDN router by flooding large amount of malicious Interests with spoofed names. To loosen the stress of PIT attacked by IFA, we propose an approach called Disabling PIT Exhaustion (DPE) to divert all the malicious Interests out of PIT, by directly recording their state information (e.g., incoming interface) in the name of each malicious Interest rather than PIT, as well as introducing a packet marking scheme to enable Data packet forwarding without the help of PIT. DPE can be considered as a security management mechanism for the emerging NDN architecture, which aims at reducing memory resource consumption for each NDN router. Moreover, we present an in-depth evaluation on DPE, via extensive simulations under realistic users' behavior model. Simulation results show DPE can significantly mitigate the damage effect of IFA on exhausting PIT's memory resource. To the best of our knowledge, DPE is the first attempt to design a security management mechanism embedding with the idea “decoupling malicious Interests from PIT” to counter IFA.","PeriodicalId":174992,"journal":{"name":"2013 IEEE Globecom Workshops (GC Wkshps)","volume":"5 6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"56","resultStr":"{\"title\":\"Decoupling malicious Interests from Pending Interest Table to mitigate Interest Flooding Attacks\",\"authors\":\"Kai Wang, Huachun Zhou, Yajuan Qin, Jia Chen, Hongke Zhang\",\"doi\":\"10.1109/GLOCOMW.2013.6825115\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Named Data Networking (NDN) is a clean slate Internet paradigm that embeds some security primitives in its original design, which is being considered as one of the promising candidates for next-generation Internet architecture. However, it may suffer from some emerging threats such as Interest Flooding Attacks (IFA), which means corresponding security management mechanisms need to be designed to improve its security. In this paper, we focus on the IFA that can severely consume the memory resource for the Pending Interest Table (PIT) of each involved NDN router by flooding large amount of malicious Interests with spoofed names. To loosen the stress of PIT attacked by IFA, we propose an approach called Disabling PIT Exhaustion (DPE) to divert all the malicious Interests out of PIT, by directly recording their state information (e.g., incoming interface) in the name of each malicious Interest rather than PIT, as well as introducing a packet marking scheme to enable Data packet forwarding without the help of PIT. DPE can be considered as a security management mechanism for the emerging NDN architecture, which aims at reducing memory resource consumption for each NDN router. Moreover, we present an in-depth evaluation on DPE, via extensive simulations under realistic users' behavior model. Simulation results show DPE can significantly mitigate the damage effect of IFA on exhausting PIT's memory resource. To the best of our knowledge, DPE is the first attempt to design a security management mechanism embedding with the idea “decoupling malicious Interests from PIT” to counter IFA.\",\"PeriodicalId\":174992,\"journal\":{\"name\":\"2013 IEEE Globecom Workshops (GC Wkshps)\",\"volume\":\"5 6 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"56\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 IEEE Globecom Workshops (GC Wkshps)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/GLOCOMW.2013.6825115\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE Globecom Workshops (GC Wkshps)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/GLOCOMW.2013.6825115","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 56

摘要

命名数据网络(NDN)是一种全新的互联网范式,它在其原始设计中嵌入了一些安全原语,被认为是下一代互联网架构的有希望的候选者之一。但是,它可能会受到一些新出现的威胁,例如兴趣泛洪攻击(IFA),这意味着需要设计相应的安全管理机制来提高其安全性。在本文中,我们关注的IFA可能会严重消耗每个涉及NDN路由器的未决兴趣表(PIT)的内存资源,因为它会淹没大量带有欺骗名称的恶意兴趣。为了减轻IFA攻击PIT的压力,我们提出了一种称为禁用PIT耗尽(DPE)的方法,通过直接以每个恶意兴趣而不是PIT的名义记录其状态信息(例如,入站接口),将所有恶意兴趣转移出PIT,并引入数据包标记方案,使数据包能够在没有PIT帮助的情况下转发。DPE可以看作是新兴NDN架构的一种安全管理机制,旨在减少每个NDN路由器的内存资源消耗。此外,我们通过在现实用户行为模型下的广泛模拟,对DPE进行了深入的评估。仿真结果表明,DPE可以显著减轻IFA耗尽PIT内存资源的损害效应。据我们所知,DPE是第一次尝试设计一种嵌入“从PIT中解耦恶意利益”思想的安全管理机制来对抗IFA。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Decoupling malicious Interests from Pending Interest Table to mitigate Interest Flooding Attacks
Named Data Networking (NDN) is a clean slate Internet paradigm that embeds some security primitives in its original design, which is being considered as one of the promising candidates for next-generation Internet architecture. However, it may suffer from some emerging threats such as Interest Flooding Attacks (IFA), which means corresponding security management mechanisms need to be designed to improve its security. In this paper, we focus on the IFA that can severely consume the memory resource for the Pending Interest Table (PIT) of each involved NDN router by flooding large amount of malicious Interests with spoofed names. To loosen the stress of PIT attacked by IFA, we propose an approach called Disabling PIT Exhaustion (DPE) to divert all the malicious Interests out of PIT, by directly recording their state information (e.g., incoming interface) in the name of each malicious Interest rather than PIT, as well as introducing a packet marking scheme to enable Data packet forwarding without the help of PIT. DPE can be considered as a security management mechanism for the emerging NDN architecture, which aims at reducing memory resource consumption for each NDN router. Moreover, we present an in-depth evaluation on DPE, via extensive simulations under realistic users' behavior model. Simulation results show DPE can significantly mitigate the damage effect of IFA on exhausting PIT's memory resource. To the best of our knowledge, DPE is the first attempt to design a security management mechanism embedding with the idea “decoupling malicious Interests from PIT” to counter IFA.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信