I-CIFA: An improved collusive interest flooding attack in named data networking

I-CIFA: An improved collusive interest flooding attack in named data networking
复制标题

I-CIFA:命名数据网络中改进的共谋利益洪泛攻击

DOI:
10.1016/j.jisa.2021.102912
复制
发表时间:
2021
影响因子:
5.6
通讯作者:
Yue Meng
Yue Meng
中科院分区:
计算机科学3区
文献类型:
--
作者:
Wu Zhijun;Feng Wenzhi;Lei Jin;Yue Meng

文献摘要

被引文献

相似文献

命名数据网络(NDN)作为一种新型的网络架构,近年来成为研究的热点,其安全性也受到了广泛关注。随着NDN网络中分布式拒绝服务(DDoS)攻击方法的不断更新,本文设计了一种新的攻击类型,称为改进型串通泛洪攻击(I-CIFA)。I-CIFA攻击综合了NDN网络中主流DDoS攻击的优点,是一种低速率DDoS攻击与串通生产者合作产生的攻击方式。I-CIFA攻击在现有DDoS攻击的基础上,进一步提高了对网络的破坏能力和对现有防御方案的抵抗能力。I-CIFA是在CIFA的基础上,通过改进攻击节点等设计的。除了重新定义和配置攻击参数外,还在两个方面进行了改进。首先,在攻击开始前增加探测路由节点的未决兴趣表(PIT)容量的探测模式;其次,进一步改进了每个攻击周期中每个攻击者向串通生产者请求数据包的方式。测试结果表明,I-CIFA可以导致整个网络中87.5%的合法兴趣数据包被丢弃,并且它不仅在网络上具有很强的攻击范围,而且现有的cifa对策也很难被检测到。
Named Data Network (NDN) as a new network architecture, in recent years become a hot research, its security has been widespread concern. With the continuous updating of distributed denial of service (DDoS) attack methods in NDN networks, this article designs a new type of attack, called the Improved Collusive Flooding Attack (I-CIFA). I-CIFA attack combines the advantages of mainstream DDoS attack in NDN network, and is an attack method generated by low-rate DDoS attack and the cooperation of collusive producer. On the basis of the existing DDoS attack, the I-CIFA attack further improves the ability to destroy the network and the ability to resist the existing defense scheme. I-CIFA is designed on the basis of CIFA by improving the attack nodes and so on. In addition to redefining and configuring the attack parameters, improvements were also made in two aspects. First, the probing mode to probe the pending interest table (PIT) capacity of the routing nodes was added before attack started. Second, the way in which each attacker requests a packet from the collusive producer in each attack cycle has been further improved. Test results show that I-CIFA can cause 87.5% of the legitimate interest packets in the whole network to be discarded, and it is not only has a strong attack range on the network, but it is also difficult to be detected by existing CIFA-countermeasures.