A Novel Interest Flooding Attacks Detection and Countermeasure Scheme in NDN

A Novel Interest Flooding Attacks Detection and Countermeasure Scheme in NDN
复制标题

DOI:
10.1109/glocom.2016.7841526
复制
发表时间:
2016-12
期刊:
2016 IEEE Global Communications Conference (GLOBECOM)
影响因子:
--
通讯作者:
Yonghui Xin;Yang Li;Wei Wang;Weiyuan Li;Xin Chen
Yonghui Xin;Yang Li;Wei Wang;Weiyuan Li;Xin Chen
中科院分区:
其他
文献类型:
--
作者:
Yonghui Xin;Yang Li;Wei Wang;Weiyuan Li;Xin Chen

文献摘要

被引文献

相似文献

命名数据网络(Named Data Networking,NDN)作为下一代网络的候选方案之一,在移动性、内容分发和安全性等方面具有TCP/IP网络无法比拟的优势。虽然NDN的设计是为了防御当前互联网中大多数的分布式拒绝服务(DDoS)攻击,但它预计会出现一些新的DDoS攻击。一种典型的DDoS形式称为兴趣泛滥攻击(IFA),它可以通过溢出PIT轻松启动,并对NDN造成不可估量的损害。现有的IFA检测和对策方法主要是基于PIT异常状态统计。然而,这些方法可能会造成误判,损害合法用户,特别是在低速率DDoS攻击或网络拥塞的情况下。本文通过监测内容请求的异常分布,提出了一种基于累积熵的IFA检测方案,并利用相对熵理论提出了恶意前缀识别方法。在检测到攻击者后,还使用了兴趣回溯对策来抑制攻击者。因此,该方案可以减少IFA的误判,保护合法用户,同时可以避免对正常流量波动的过度反应。仿真结果表明,我们的方法可以有效地减轻NDN中的IFA。
As one of the promising candidates for the next generation network, Named Data Networking (NDN) has more advantages than the TCP/IP network in areas such as mobility, content distribution and security. Although NDN is designed to defense the majority Distributed Denial of Service (DDoS) attack in the current Internet, it anticipates some new varietal DDoS attacks. A representative DDoS form is called Interest Flooding Attacks (IFA), which can be launched easily by overflowing the PIT and can do immeasurable damage to the NDN. The existing IFA detection and countermeasure methods are mainly based on the PIT abnormal state statistics. However, these methods may cause misjudgment and damage the legitimate users, especially in the case of low-rate DDoS attacks or network congestion. In this paper, we propose an IFA detection scheme based on cumulative entropy by monitoring the content request abnormal distribution and then provide the malicious prefix identification method by relative entropy theory. An Interest traceback countermeasure is also used to restrain the attacker after detection. Therefore, the proposed scheme can reduce the IFA misjudgment and protect the legitimate user, and at the same time, can avoid overreaction to normal traffic fluctuation. Simulation results reveal that our methods can effectively mitigate the IFA in NDN.