Title :
Poseidon: Mitigating interest flooding DDoS attacks in Named Data Networking
Author :
Compagno, Alberto ; Conti, Marco ; Gasti, Paolo ; Tsudik, Gene
Author_Institution :
Univ. of Padua, Padua, Italy
Abstract :
Content-Centric Networking (CCN) is an emerging networking paradigm being considered as a possible replacement for the current IP-based host-centric Internet infrastructure. CCN focuses on content distribution, which is arguably not well served by IP. Named-Data Networking (NDN) is an example of CCN. NDN is also an active research project under the NSF Future Internet Architectures (FIA) program. FIA emphasizes security and privacy from the outset and by design. To be a viable Internet architecture, NDN must be resilient against current and emerging threats. This paper focuses on distributed denial-of-service (DDoS) attacks; in particular we address interest flooding, an attack that exploits key architectural features of NDN. We show that an adversary with limited resources can implement such attack, having a significant impact on network performance. We then introduce Poseidon: a framework for detecting and mitigating interest flooding attacks. Finally, we report on results of extensive simulations assessing proposed countermeasure.
Keywords :
IP networks; Internet; computer network security; CCN; FIA program; IP-based host-centric Internet infrastructure; NDN; NSF program; Poseidon; content-centric networking; distributed denial-of-service attacks; future Internet architectures program; interest flooding DDoS attacks mitigation; named-data networking; Bandwidth; Collaboration; Computer crime; Conferences; Internet; Topology;
Conference_Titel :
Local Computer Networks (LCN), 2013 IEEE 38th Conference on
Conference_Location :
Sydney, NSW
Print_ISBN :
978-1-4799-0536-2
DOI :
10.1109/LCN.2013.6761300