Title :
Attack-Resistant Distributed Time Synchronization for Virtual Private Networks
Author :
Rossberg, Michael ; Golembewski, Rene ; Schaefer, Guenter
Author_Institution :
Ilmenau Univ. of Technol., Ilmenau, Germany
fDate :
July 30 2012-Aug. 2 2012
Abstract :
To securely exchange data over public networks, such as the Internet, organizations often utilize Virtual Private Networks (VPNs). However, relying on these potentially large overlay networks makes them vital targets for Denial-of-Service(DoS) attacks. Thus, recent approaches for VPN auto-configuration address DoS resistance by employing distributed management algorithms. Nevertheless, there is no satisfying solution for time synchronization within VPNs that is designed for resistance against DoS as well as internal attacks. For example, NTP relies on hierarchical structures, and cannot comply with DoS resistance. Thus, in this article we present a novel, fully distributed and fault tolerant time synchronization approach, which is designed to be transparently integrated in VPN gateways. Combining diffusion- based round-trip-synchronization with an internal attacker detection, the proposed mechanism is making a contribution to resilient VPN design. Simulation results reveal a robustness against rather powerful internal attackers.
Keywords :
computer network security; distributed processing; fault tolerance; internetworking; synchronisation; virtual private networks; DoS attacks; VPN auto-configuration; VPN gateways; attack-resistant distributed time synchronization; denial-of-service attacks; diffusion-based round-trip-synchronization; distributed management algorithms; fault tolerant time synchronization approach; internal attacker detection; overlay networks; virtual private networks; Clocks; Delay; Peer to peer computing; Resistance; Robustness; Synchronization; Virtual private networks;
Conference_Titel :
Computer Communications and Networks (ICCCN), 2012 21st International Conference on
Conference_Location :
Munich
Print_ISBN :
978-1-4673-1543-2
DOI :
10.1109/ICCCN.2012.6289288