Securing QoS threats to RSVP messages and their countermeasures
Securing QoS threats to RSVP messages and their countermeasures
复制标题
RSVP消息的QoS威胁及其对策
DOI:
10.1109/iwqos.1999.766479
复制
发表时间:
1999
期刊:
影响因子:
--
通讯作者:
F. Gong
中科院分区:
文献类型:
--
作者:
Tsung;S.F. Wu;Z. Fu;He Huang;F. Gong
In this paper, we study one type of DoQoNS (denial of quality of network service) attacks: attacks directly on the resource reservation and setup protocol. Particularly, we have studied and analyzed the RSVP protocol. Two contributions are: first, we performed a security analysis on RSVP which demonstrates the key vulnerabilities of its distributed resource reservation and setup process. Second, we proposed a new secure RSVP protocol, SDS/CD (selective digital signature with conflict detection), which combines the strength of attack prevention and intrusion detection. SDS/CD resolves a fundamental issue in network security: how to protect the integrity, in an end-to-end fashion, of a target object that is mutable along the route path. As a result, we will show that SDS/CD can deal with many insider attacks that can not be handled by the current IETF/RSVP security solution: hop-by-hop authentication.