论文标题

logdos:基于路径标识符的基于路径标识符的基于记录的新型DDOS预防机制中心网络

LogDos: A Novel Logging-based DDoS Prevention Mechanism in Path Identifier-Based Information Centric Networks

论文作者

Al-Duwairi, Basheer, Ozkasap, Oznur, Uysal, Ahmet, Kocaogullar, Ceren, Yildirim, Kaan

论文摘要

近年来,以信息为中心的网络(ICN)是下一代互联网的新网络范式。这些网络的主要目标是根据网络内内容缓存提供有效的内容分布和检索的机制。不同ICN架构的设计解决了传统互联网中发现的许多安全问题。因此,允许通过Internet进行安全,可靠和可扩展的通信。但是,最近的研究表明,这些体系结构容易受到不同类型的DDOS攻击。在本文中,我们提出了一种防御机制,以反对基于路径识别者信息中心网络中的分布式拒绝服务攻击(DDOS)。所提出的称为LogDos的机制执行基于GET消息记录的过滤,并采用基于Bloom Filter的日志记录来存储输入消息,以便对相应的内容消息进行验证,同时筛选源自恶意主机的数据包。我们开发了三个版本的logDos,在启用LogDOS的路由器处的存储开销级别不同。广泛的仿真实验表明,LogDos在DDOS攻击方面非常有效,因为它可以在不同的攻击场景中过滤超过99.98%的攻击流量,同时又产生可接受的存储开销。

Information Centric Networks (ICNs) have emerged in recent years as a new networking paradigm for the next-generation Internet. The primary goal of these networks is to provide effective mechanisms for content distribution and retrieval based on in-network content caching. The design of different ICN architectures addressed many of the security issues found in the traditional Internet. Therefore, allowing for a secure, reliable, and scalable communication over the Internet. However, recent research studies showed that these architectures are vulnerable to different types of DDoS attacks. In this paper, we propose a defense mechanism against distributed denial of service attacks (DDoS) in path-identifier based information centric networks. The proposed mechanism, called LogDos, performs GET Message logging based filtering and employs Bloom filter based logging to store incoming GET messages such that corresponding content messages are verified, while filtering packets originating from malicious hosts. We develop three versions of LogDos with varying levels of storage overhead at LogDos-enabled router. Extensive simulation experiments show that LogDos is very effective against DDoS attacks as it can filter more than 99.98 % of attack traffic in different attack scenarios while incurring acceptable storage overhead.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源