DocumentCode :
2779400
Title :
Self-Routing Denial-of-Service Resistant Capabilities Using In-packet Bloom Filters
Author :
Rothenberg, Christian Esteve ; Jokela, Petri ; Nikander, Pekka ; Sarela, Mikko ; Ylitalo, Jukka
Author_Institution :
Sch. of Electr. & Comput. Eng., Univ. of Campinas, Campinas, Brazil
fYear :
2009
fDate :
9-10 Nov. 2009
Firstpage :
46
Lastpage :
51
Abstract :
In this paper, we propose and analyze an in-packet Bloom-filter-based source-routing architecture resistant to Distributed Denial-of-Service attacks. The approach is based on forwarding identifiers that act simultaneously as path designators, i.e. define which path the packet should take, and as capabilities, i.e. effectively allowing the forwarding nodes along the path to enforce a security policy where only explicitly authorized packets are forwarded. The compact representation is based on a small Bloom filter whose candidate elements (i.e. link names) are dynamically computed at packet forwarding time using a loosely synchronized time-based shared secret and additional in-packet flow information (e.g., invariant packet contents). The capabilities are thus expirable and flow-dependent, but do not require any per-flow network state or memory look-ups, which have been traded-off for additional, though amenable, per-packet computation. Our preliminary security analysis suggests that the self-routing capabilities can be an effective building block towards DDoS-resistant network architectures.
Keywords :
computer network security; telecommunication network routing; DDoS resistant network architectures; denial-of-service resistant capabilities; in-packet bloom filters; in-packet flow information; security analysis; source routing architecture; synchronized time based shared secret; Bandwidth; Computer architecture; Computer crime; Computer networks; Cryptography; Filters; Information security; Network topology; Resistance; Routing; Bloom filters; Denial-of-Service; capabilities; publish subscribe; source routing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Network Defense (EC2ND), 2009 European Conference on
Conference_Location :
Milan
Print_ISBN :
978-1-4244-6049-6
Type :
conf
DOI :
10.1109/EC2ND.2009.14
Filename :
5494331
Link To Document :
بازگشت