DocumentCode :
2437681
Title :
The Taming of the Shrew: Mitigating Low-Rate TCP-Targeted Attack
Author :
Chang, Chia-Wei ; Lee, Seungjoon ; Lin, Bill ; Wang, Jia
Author_Institution :
Univ. of California San Diego, La Jolla, CA, USA
fYear :
2009
fDate :
22-26 June 2009
Firstpage :
137
Lastpage :
144
Abstract :
A Shrew attack, which uses a low-rate burst carefully designed to exploit TCP´s retransmission timeout mechanism, can throttle the bandwidth of a TCP flow in a stealthy manner. While such an attack can significantly degrade the performance of all TCP-based protocols and services including Internet routing (e.g., BGP), no existing scheme clearly solves the problem in real network scenarios. In this paper, we propose a simple protection mechanism, called SAP (Shrew Attack Protection), for defending against a Shrew attack. Rather than attempting to track and isolate Shrew attackers, SAP identifies TCP victims by monitoring their drop rates and preferentially admits those packets from victims with high drop rates to the output queue. This is to ensure that well-behaved TCP sessions can retain their bandwidth shares. Our simulations indicate that under a Shrew attack, SAP can prevent TCP sessions from closing, and effectively enable TCP flows to maintain high throughput. SAP is a destination-port-based mechanism and requires only a small number of counters to find potential victims, which makes SAP readily implementable on top of existing router mechanisms.
Keywords :
security of data; telecommunication security; transport protocols; Internet routing; TCP flow; TCP retransmission timeout mechanism; TCP sessions; TCP-based protocols; TCP-targeted attack; destination-port-based mechanism; router mechanism; shrew attack protection; transmission control protocols; transport protocols; Aggregates; Bandwidth; Counting circuits; Distributed computing; Frequency synchronization; IP networks; Monitoring; Protection; Routing protocols; Throughput; Network Security; Shrew attack;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems, 2009. ICDCS '09. 29th IEEE International Conference on
Conference_Location :
Montreal, QC
ISSN :
1063-6927
Print_ISBN :
978-0-7695-3659-0
Electronic_ISBN :
1063-6927
Type :
conf
DOI :
10.1109/ICDCS.2009.9
Filename :
5158418
Link To Document :
بازگشت