RED-FT: A Scalable Random Early Detection Scheme with Flow Trust against DoS Attacks

RED-FT: A Scalable Random Early Detection Scheme with Flow Trust against DoS Attacks
复制标题

DOI:
10.1109/lcomm.2013.022713.122652
复制
发表时间:
2013-03
期刊:
IEEE Communications Letters
影响因子:
--
通讯作者:
Xianliang Jiang;Jiangang Yang;Guang Jin;Wei Wei-Wei
Xianliang Jiang;Jiangang Yang;Guang Jin;Wei Wei-Wei
中科院分区:
其他
文献类型:
--
作者:
Xianliang Jiang;Jiangang Yang;Guang Jin;Wei Wei-Wei

文献摘要

被引文献

相似文献

在传统的主动队列管理算法中,例如RED,使用数据包的源和目标 IP 地址定义的每个流,公平地竞争瓶颈队列的缓存。但无法识别恶意流量。它可以实现潜在的网络层攻击,例如泛洪拒绝服务 (DoS) 攻击和低速率 DoS 攻击。在这封信中,我们提出了一种使用流信任值来防御 DoS 攻击的新方案。与以往方案不同的是,它利用流信任来保护合法流。路由器监控网络流量并计算流量信任值,用于相关的队列管理。恶意流量的信任值较低,而合法流量的信任值较高。仿真结果表明,与现有的队列管理算法相比,该方案在DoS攻击场景下提高了吞吐量和延迟。我们认为该方案对于保护网络安全是实用且有效的。
In traditional Active Queue Management algorithms, e.g. RED, each flow, defined with the source and destination IP address of packets, fairly contends for the cache of bottleneck queues. However a malicious flow cannot be identified. And it enables potential network-layer attacks, e.g. the flooding Denial-of-Service (DoS) attack and the low-rate DoS attack. In this letter, we propose a new scheme using the flows trust values to defend against DoS attacks. Different from previous schemes, it employs the flow trust to safeguard legitimate flows. A router monitors network flows and calculates flows trust values, which are used for the relevant queue management. Malicious flows would be with lower trust values while legitimate flows would be with higher ones. Simulation results show that the scheme improves the throughput and delay in DoS attacking scenarios comparing with existing queue management algorithms. We consider the scheme is practical and effective to secure networks.