DocumentCode :
1823401
Title :
Reduction of quality (RoQ) attacks on Internet end-systems
Author :
Guirguis, Mina ; Bestavros, Azer ; Matta, Ibrahim ; Zhang, Yuting
Author_Institution :
Dept. of Comput. Sci., Boston Univ., MA, USA
Volume :
2
fYear :
2005
fDate :
13-17 March 2005
Firstpage :
1362
Abstract :
Current computing systems depend on adaptation mechanisms to ensure that they remain in quiescent operating regions. These regions are often defined using efficiency, fairness, and stability properties. To that end, traditional research works in scalable server architectures and protocols have focused on promoting these properties by proposing even more sophisticated adaptation mechanisms, without the proper attention to security implications. In this paper, we exemplify such security implications by exposing the vulnerabilities of admission control mechanisms that are widely deployed in Internet end systems to reduction of quality (RoQ) attacks. RoQ attacks target the transients of a system´s adaptive behavior as opposed to its limited steady-state capacity. We show that a well orchestrated RoQ attack on an end-system admission control policy could introduce significant inefficiencies that could potentially deprive an Internet end-system from much of its capacity, or significantly reduce its service quality, while evading detection by consuming an unsuspicious, small fraction of that system´s hijacked capacity. We develop a control theoretic model for assessing the impact of RoQ attacks on an end-system´s admission controller. We quantify the damage inflicted by an attacker through deriving appropriate metrics. We validate our findings through real Internet experiments performed in our lab.
Keywords :
Internet; computer network management; computer network reliability; network servers; performance evaluation; personal computing; quality of service; telecommunication congestion control; telecommunication security; transport protocols; Internet end system; RoQ; Web service; admission control mechanisms; denial-of-service; performance evaluation; protocols; reduction of quality attacks; resource management; scalable server architectures; security; sophisticated adaptation mechanisms; stability; steady-state capacity; systems hijacked capacity; vulnerability; Admission control; Computer architecture; Computer science; Delay; Internet; Mechanical factors; Protocols; Resource management; Stability; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2005. 24th Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings IEEE
ISSN :
0743-166X
Print_ISBN :
0-7803-8968-9
Type :
conf
DOI :
10.1109/INFCOM.2005.1498361
Filename :
1498361
Link To Document :
بازگشت