• DocumentCode
    762922
  • Title

    IP easy-pass: a light-weight network-edge resource access control

  • Author

    Wang, Haining ; Bose, Abhijit ; El-Gendy, Mohamed ; Shin, Kang G.

  • Author_Institution
    Dept. of Comput. Sci., Coll. of William & Mary, Williamsburg, VA, USA
  • Volume
    13
  • Issue
    6
  • fYear
    2005
  • Firstpage
    1247
  • Lastpage
    1260
  • Abstract
    Providing real-time communication services to multimedia applications and subscription-based Internet access often requires that sufficient network resources be reserved for real-time traffic. However, the reserved network resource is susceptible to resource theft and abuse. Without a resource access control mechanism that can efficiently differentiate legitimate real-time traffic from attacking packets, the traffic conditioning and policing enforced at Internet Service Provider (ISP) edge routers cannot protect the reserved network resource from embezzlement. On the contrary to the usual expectation, the traffic policing at edge routers aggravates their vulnerability to flooding attacks by blindly dropping packets. In this paper, we propose a fast and lightweight IP network-edge resource access control mechanism, called IP Easy-pass, to prevent unauthorized access to reserved network resources at edge devices. We attach a unique pass to each legitimate real-time packet so that an ISP edge router can validate the legitimacy of the incoming IP packet very quickly and simply by checking its pass. We present the generation of Easy-pass, its embedding, and verification procedures. We implement the IP Easy-pass mechanism in the Linux kernel, and measure its overhead on our testbed. Finally, we demonstrate its effectiveness against packet forgery and resource embezzlement attempts by conducting a series of experiments.
  • Keywords
    IP networks; Internet; real-time systems; resource allocation; telecommunication network routing; telecommunication security; telecommunication traffic; IP easy-pass; Internet service provider edge routers; Linux kernel; blindly dropping packets; flooding attacks; light-weight network-edge resource access control; multimedia applications; real-time communication services; real-time traffic; subscription-based Internet access; traffic policing; Access control; Communication system traffic control; Floods; IP networks; Kernel; Linux; Multimedia communication; Protection; Testing; Web and internet services; Network QoS; resource access control;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2005.860113
  • Filename
    1561221