DocumentCode
3697233
Title
Analysis and Comparison of the Network Security Protocol with DoS/DDoS Attack Resistance Performance
Author
Linzhi Jiang;Chunxiang Xu;Xiaofang Wang;Yanghong Zhou
Author_Institution
Sch. of Comput. Sci. &
fYear
2015
Firstpage
1785
Lastpage
1790
Abstract
Network security protocol design is important aspectof network security research. DoS/DDoS is very seriousattack in wired and wireless network. DoS/DDoS attack depletes memory/cpu of service provider, so legitimate user can´t gain normal service. According to anti-DoS attack strategy of network security protocols, we give and discuss three mechanisms (stateless connection, Fail-together and Subset Sum Client-Puzzle) on design of a key exchange protocol against denial of service attack for ISO/IEC1170-3 key exchange protocol. Subset SumClient-Puzzle has simple structure, Non-Parallelizable speciality and fast verification. N Subset Sum Client-Puzzles´ difficulties are sum of n Subset Sum Client-Puzzle´s difficulty. Based on analysis of new key exchange protocol, we compare initiator and responder for computation resource, memory depletion and anti-DoS/DDoS. ISO/IEC1170-3 key exchange protocol on Subset Sum Client Puzzle, which is non-parallelizable, easy construction and verification, has the good property against DoS/DDoS attack. It provides a very good reference for network security protocol design with anti-DoS/DDoS attack.
Keywords
"Protocols","Computer crime","Authentication","IEC","ISO","Servers"
Publisher
ieee
Conference_Titel
High Performance Computing and Communications (HPCC), 2015 IEEE 7th International Symposium on Cyberspace Safety and Security (CSS), 2015 IEEE 12th International Conferen on Embedded Software and Systems (ICESS), 2015 IEEE 17th International Conference on
Type
conf
DOI
10.1109/HPCC-CSS-ICESS.2015.148
Filename
7336430
Link To Document