• DocumentCode
    27628
  • Title

    PBS: Signaling architecture for network traffic authorization

  • Author

    Se Gi Hong ; Schulzrinne, H.

  • Volume
    51
  • Issue
    7
  • fYear
    2013
  • fDate
    Jul-13
  • Firstpage
    89
  • Lastpage
    96
  • Abstract
    We propose a signaling architecture for network traffic authorization, called Permission-Based Sending (PBS), aiming to prevent DoS attacks and other forms of unauthorized traffic. Toward this goal, PBS takes a hybrid approach: a proactive approach of explicit permissions and a reactive approach of monitoring and countering attacks. PBS uses a concept similar to existing capability-based systems in the manner in which the sender should get authorization (permission) from a receiver for flows. However, PBS introduces new and practical approaches to overcome the deficiencies (the difficulty of obtaining permission and incompatibility with current network architecture) of those systems. On-path signaling enables easy installation and management of the permission state. Working on current network protocols supports compatibility and allows PBS to be deployed in existing networks. In addition, a monitoring mechanism provides a second line of defense against attacks. Our analysis and performance evaluation show that PBS is an effective and scalable solution to prevent several kinds of attacks, and improves the resilience of the system against network failure by using soft-state mechanisms.
  • Keywords
    computer network reliability; computer network security; telecommunication signalling; DoS attack; On-path signaling; PBS; capability based system; network failure; network protocol; network traffic authorization; permission based sending; signaling architecture; soft state mechanism; system resiliency; Authentication; IP networks; Protocols; Public key cryptography; Signal processing; Telecommunication traffic;
  • fLanguage
    English
  • Journal_Title
    Communications Magazine, IEEE
  • Publisher
    ieee
  • ISSN
    0163-6804
  • Type

    jour

  • DOI
    10.1109/MCOM.2013.6553683
  • Filename
    6553683