Securing QoS threats to RSVP messages and their countermeasures

Securing QoS threats to RSVP messages and their countermeasures
复制标题

RSVP消息的QoS威胁及其对策

DOI:
10.1109/iwqos.1999.766479
复制
发表时间:
1999
期刊:
1999 Seventh International Workshop on Quality of Service. IWQoS'99. (Cat. No.98EX354)
影响因子:
--
通讯作者:
F. Gong
F. Gong
中科院分区:
--
文献类型:
--
作者:
Tsung;S.F. Wu;Z. Fu;He Huang;F. Gong

文献摘要

被引文献

相似文献

在本文中,我们研究了一种类型的DoQoNS(拒绝网络服务质量)攻击:攻击的资源预留和设置协议直接。特别是对RSVP协议进行了研究和分析。两个贡献是:首先对RSVP协议进行了安全性分析,揭示了其分布式资源预留和建立过程中的关键漏洞。其次,结合攻击防御和入侵检测的优点,提出了一种新的安全RSVP协议SDS/CD(selective digital signature with conflict detection)。SDS/CD解决了网络安全中的一个基本问题:如何以端到端的方式保护沿着路由路径可变的目标对象的完整性,从而证明SDS/CD可以处理当前IETF/RSVP安全解决方案逐跳认证所不能处理的许多内部攻击。
In this paper, we study one type of DoQoNS (denial of quality of network service) attacks: attacks directly on the resource reservation and setup protocol. Particularly, we have studied and analyzed the RSVP protocol. Two contributions are: first, we performed a security analysis on RSVP which demonstrates the key vulnerabilities of its distributed resource reservation and setup process. Second, we proposed a new secure RSVP protocol, SDS/CD (selective digital signature with conflict detection), which combines the strength of attack prevention and intrusion detection. SDS/CD resolves a fundamental issue in network security: how to protect the integrity, in an end-to-end fashion, of a target object that is mutable along the route path. As a result, we will show that SDS/CD can deal with many insider attacks that can not be handled by the current IETF/RSVP security solution: hop-by-hop authentication.