DocumentCode :
3454193
Title :
Enhancing Internet robustness against malicious flows using active queue management
Author :
Zheng, Jun ; Hu, Mingzeng ; Zhao, Liyuan
Author_Institution :
Dept. of Comput. Sci., Harbin Inst. of Technol., China
fYear :
2005
fDate :
16-18 Dec. 2005
Abstract :
Attackers can easily modify the TCP control protocols of host computers to inject the malicious flows to the Internet. Including DDoS and worm attack flows, these malicious flows are unresponsive to the congestion control mechanism which is necessary to the equilibrium of the whole Internet. In this paper, a new scheme against the large scale malicious flows is proposed based on the principles of TCP congestion control. The kernel is to implement a new scheduling algorithm named as CCU (compare and control unresponsive flows) which is one sort of active queue management (AQM). According to the unresponsive characteristic of malicious flows, CCU algorithm relies on the two processes of malicious flows - detection and punishment. The elastics control mechanism of unresponsive flows benefits the AQM with the high performance and enhances the Internet robustness against malicious flows. The network resource can be regulated for the basic quality of service (QoS) demands of legal users. The experiments prove that CCU can detect and restrain responsive flows more accurately compared to other AQM algorithms.
Keywords :
Internet; quality of service; queueing theory; scheduling; security of data; telecommunication congestion control; telecommunication network management; telecommunication security; transport protocols; DDoS attack flow; Internet; TCP congestion control; TCP control protocols; active queue management; compare and control unresponsive flows; host computers; quality of service; scheduling algorithm; worm attack flow; Computer worms; Internet; Kernel; Large-scale systems; Law; Protocols; Quality of service; Robust control; Robustness; Scheduling algorithm;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Embedded Software and Systems, 2005. Second International Conference on
Print_ISBN :
0-7695-2512-1
Type :
conf
DOI :
10.1109/ICESS.2005.52
Filename :
1609918
Link To Document :
بازگشت