DocumentCode
3171748
Title
Attack-Resistant Distributed Time Synchronization for Virtual Private Networks
Author
Rossberg, Michael ; Golembewski, Rene ; Schaefer, Guenter
Author_Institution
Ilmenau Univ. of Technol., Ilmenau, Germany
fYear
2012
fDate
July 30 2012-Aug. 2 2012
Firstpage
1
Lastpage
8
Abstract
To securely exchange data over public networks, such as the Internet, organizations often utilize Virtual Private Networks (VPNs). However, relying on these potentially large overlay networks makes them vital targets for Denial-of-Service(DoS) attacks. Thus, recent approaches for VPN auto-configuration address DoS resistance by employing distributed management algorithms. Nevertheless, there is no satisfying solution for time synchronization within VPNs that is designed for resistance against DoS as well as internal attacks. For example, NTP relies on hierarchical structures, and cannot comply with DoS resistance. Thus, in this article we present a novel, fully distributed and fault tolerant time synchronization approach, which is designed to be transparently integrated in VPN gateways. Combining diffusion- based round-trip-synchronization with an internal attacker detection, the proposed mechanism is making a contribution to resilient VPN design. Simulation results reveal a robustness against rather powerful internal attackers.
Keywords
computer network security; distributed processing; fault tolerance; internetworking; synchronisation; virtual private networks; DoS attacks; VPN auto-configuration; VPN gateways; attack-resistant distributed time synchronization; denial-of-service attacks; diffusion-based round-trip-synchronization; distributed management algorithms; fault tolerant time synchronization approach; internal attacker detection; overlay networks; virtual private networks; Clocks; Delay; Peer to peer computing; Resistance; Robustness; Synchronization; Virtual private networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Communications and Networks (ICCCN), 2012 21st International Conference on
Conference_Location
Munich
Print_ISBN
978-1-4673-1543-2
Type
conf
DOI
10.1109/ICCCN.2012.6289288
Filename
6289288
Link To Document