DocumentCode :
3382770
Title :
Game-based analysis of denial-of-service prevention protocols
Author :
Mahimkar, Ajay ; Shmatikov, Vitaly
Author_Institution :
Dept. of Electr. & Comput. Eng., Texas Univ., Austin, TX, USA
fYear :
2005
fDate :
20-22 June 2005
Firstpage :
287
Lastpage :
301
Abstract :
Availability is a critical issue in modern distributed systems. While many techniques and protocols for preventing denial of service (DoS) attacks have been proposed and deployed in recent years, formal methods for analyzing and proving them correct have not kept up with the state of the art in DoS prevention. This paper proposes a new protocol for preventing malicious bandwidth consumption, and demonstrates how game-based formal methods can be successfully used to verify availability-related security properties of network protocols. We describe two classes of DoS attacks aimed at bandwidth consumption and resource exhaustion, respectively. We then propose our own protocol, based on a variant of client puzzles, to defend against bandwidth consumption, and use the JFKr key exchange protocol as an example of a protocol that defends against resource exhaustion attacks. We specify both protocols as alternating transition systems (ATS), state their security properties in alternating-time temporal logic (ATL) and verify them using MOCHA, a model checker that has been previously used to analyze fair exchange protocols.
Keywords :
formal verification; protocols; security of data; temporal logic; DoS attacks; JFKr key exchange protocol; MOCHA; alternating transition systems; alternating-time temporal logic; denial-of-service prevention protocols; fair exchange protocols; game-based analysis; game-based formal methods; malicious bandwidth consumption prevention; network protocols; resource exhaustion attacks; Availability; Bandwidth; Computer crime; Distributed computing; Filters; Floods; Logic; Protection; Protocols; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Foundations, 2005. CSFW-18 2005. 18th IEEE Workshop
ISSN :
1063-6900
Print_ISBN :
0-7695-2340-4
Type :
conf
DOI :
10.1109/CSFW.2005.18
Filename :
1443213
Link To Document :
بازگشت