• DocumentCode
    687682
  • Title

    Mitigating congestion-based denial of service attacks with active queue management

  • Author

    Bedi, Harkeerat ; Roy, Sandip ; Shiva, Sajjan

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Memphis, Memphis, TN, USA
  • fYear
    2013
  • fDate
    9-13 Dec. 2013
  • Firstpage
    1440
  • Lastpage
    1445
  • Abstract
    Denial of service (DoS) attacks are currently one of the biggest risks any organization connected to the Internet can face. Hence, the congestion handling techniques at its edge router(s), such as active queue management (AQM) schemes must consider possibilities of such attacks. Ideally, an AQM scheme should (a) ensure that each network flow gets its fair share of bandwidth, and (b) identify attack flows so that corrective actions (e.g. drop flooding traffic) can be explicitly taken against them to further mitigate the DoS attacks. This paper presents a proof-of-concept work on devising such an AQM scheme, which we name Deterministic Fair Sharing (DFS). Most of the existing AQM schemes do not achieve the above goals or have a significant room for improvement. DFS uses the concept of weighted fair share (wfs) which allows it to dynamically self-adjust the router buffer usage based on the current level of congestion, while assuring fairness among flows and aiding in identifying the malicious ones. We demonstrate the performance of DFS via extensive simulation and compare against other existing AQM techniques.
  • Keywords
    Internet; computer network security; queueing theory; telecommunication network routing; telecommunication traffic; AQM schemes; DFS; DoS attacks; Internet; active queue management; attack flows; congestion handling techniques; denial of service; deterministic fair sharing; drop flooding traffic; edge router; network flow; router buffer usage; weighted fair share; Bandwidth; Bit rate; Computer crime; Data structures; Inductors; Quality of service; Reliability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2013 IEEE
  • Conference_Location
    Atlanta, GA
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2013.6831276
  • Filename
    6831276