...
首页> 外文期刊>IEEE/ACM Transactions on Networking >TVA: A DoS-Limiting Network Architecture
【24h】

TVA: A DoS-Limiting Network Architecture

机译:TVA:DoS限制网络架构

获取原文
获取原文并翻译 | 示例
           

摘要

We motivate the capability approach to network denial-of-service (DoS) attacks, and evaluate the Traffic Validation Architecture (TVA) architecture which builds on capabilities. With our approach, rather than send packets to any destination at any time, senders must first obtain “permission to send” from the receiver, which provides the permission in the form of capabilities to those senders whose traffic it agrees to accept. The senders then include these capabilities in packets. This enables verification points distributed around the network to check that traffic has been authorized by the receiver and the path in between, and hence to cleanly discard unauthorized traffic. To evaluate this approach, and to understand the detailed operation of capabilities, we developed a network architecture called TVA. TVA addresses a wide range of possible attacks against communication between pairs of hosts, including spoofed packet floods, network and host bottlenecks, and router state exhaustion. We use simulations to show the effectiveness of TVA at limiting DoS floods, and an implementation on Click router to evaluate the computational costs of TVA. We also discuss how to incrementally deploy TVA into practice.
机译:我们鼓励采用能力方法来进行网络拒绝服务(DoS)攻击,并评估基于能力的流量验证体系结构(TVA)体系结构。使用我们的方法,发送者必须首先从接收者那里获得“发送许可”,而不是随时将数据包发送到任何目的地,这将以能力的形式向那些同意接受其流量的发送者提供许可。然后,发送方将这些功能包括在数据包中。这使分布在网络上的验证点能够检查流量是否已被接收方及其之间的路径授权,从而干净地丢弃了未经授权的流量。为了评估这种方法并了解功能的详细操作,我们开发了一种称为TVA的网络体系结构。 TVA解决了针对成对的主机对之间通信的各种可能的攻击,包括欺骗性的数据包泛滥,网络和主机瓶颈以及路由器状态耗尽。我们使用仿真来显示TVA在限制DoS泛洪方面的有效性,并使用Click路由器上的实现来评估TVA的计算成本。我们还将讨论如何逐步将TVA部署到实践中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号