...
首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Mitigating Distributed Denial of Service Attacks in Multiparty Applications in the Presence of Clock Drifts
【24h】

Mitigating Distributed Denial of Service Attacks in Multiparty Applications in the Presence of Clock Drifts

机译:在存在时钟漂移的情况下缓解多方应用程序中的分布式拒绝服务攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Network-based applications commonly open some known communication port(s), making themselves easy targets for (distributed) Denial of Service (DoS) attacks. Earlier solutions for this problem are based on port-hopping between pairs of processes which are synchronous or exchange acknowledgments. However, acknowledgments, if lost, can cause a port to be open for longer time and thus be vulnerable, while time servers can become targets to DoS attack themselves. Here, we extend port-hopping to support multiparty applications, by proposing the BIGWHEEL algorithm, for each application server to communicate with multiple clients in a port-hopping manner without the need for group synchronization. Furthermore, we present an adaptive algorithm, HOPERAA, for enabling hopping in the presence of bounded asynchrony, namely, when the communicating parties have clocks with clock drifts. The solutions are simple, based on each client interacting with the server independently of the other clients, without the need of acknowledgments or time server(s). Further, they do not rely on the application having a fixed port open in the beginning, neither do they require the clients to get a "first-contactȁD; port from a third party. We show analytically the properties of the algorithms and also study experimentally their success rates, confirm the relation with the analytical bounds.
机译:基于网络的应用程序通常会打开一些已知的通信端口,从而使它们很容易成为(分布式)拒绝服务(DoS)攻击的目标。早先的解决方案基于同步或交换确认的成对进程之间的端口跳跃。但是,如果丢失了确认,则可能导致端口打开更长时间,因此容易受到攻击,而时间服务器可能成为自己进行DoS攻击的目标。在这里,我们通过提出BIGWHEEL算法,将端口跳跃扩展为支持多方应用程序,以便每个应用程序服务器以端口跳跃的方式与多个客户端进行通信,而无需进行组同步。此外,我们提出了一种自适应算法HOPERAA,用于在有界异步的情况下(即,当通信方的时钟带有时钟漂移时)进行跳频。该解决方案很简单,基于每个客户端独立于其他客户端与服务器交互,而无需确认或时间服务器。此外,他们不依赖于一开始就开放固定端口的应用程序,也不要求客户从第三方获得“第一联系人-D;端口”。我们分析了算法的性能,并进行了实验研究他们的成功率,确定与分析范围的关系。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号