• DocumentCode
    2437681
  • Title

    The Taming of the Shrew: Mitigating Low-Rate TCP-Targeted Attack

  • Author

    Chang, Chia-Wei ; Lee, Seungjoon ; Lin, Bill ; Wang, Jia

  • Author_Institution
    Univ. of California San Diego, La Jolla, CA, USA
  • fYear
    2009
  • fDate
    22-26 June 2009
  • Firstpage
    137
  • Lastpage
    144
  • Abstract
    A Shrew attack, which uses a low-rate burst carefully designed to exploit TCP´s retransmission timeout mechanism, can throttle the bandwidth of a TCP flow in a stealthy manner. While such an attack can significantly degrade the performance of all TCP-based protocols and services including Internet routing (e.g., BGP), no existing scheme clearly solves the problem in real network scenarios. In this paper, we propose a simple protection mechanism, called SAP (Shrew Attack Protection), for defending against a Shrew attack. Rather than attempting to track and isolate Shrew attackers, SAP identifies TCP victims by monitoring their drop rates and preferentially admits those packets from victims with high drop rates to the output queue. This is to ensure that well-behaved TCP sessions can retain their bandwidth shares. Our simulations indicate that under a Shrew attack, SAP can prevent TCP sessions from closing, and effectively enable TCP flows to maintain high throughput. SAP is a destination-port-based mechanism and requires only a small number of counters to find potential victims, which makes SAP readily implementable on top of existing router mechanisms.
  • Keywords
    security of data; telecommunication security; transport protocols; Internet routing; TCP flow; TCP retransmission timeout mechanism; TCP sessions; TCP-based protocols; TCP-targeted attack; destination-port-based mechanism; router mechanism; shrew attack protection; transmission control protocols; transport protocols; Aggregates; Bandwidth; Counting circuits; Distributed computing; Frequency synchronization; IP networks; Monitoring; Protection; Routing protocols; Throughput; Network Security; Shrew attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems, 2009. ICDCS '09. 29th IEEE International Conference on
  • Conference_Location
    Montreal, QC
  • ISSN
    1063-6927
  • Print_ISBN
    978-0-7695-3659-0
  • Electronic_ISBN
    1063-6927
  • Type

    conf

  • DOI
    10.1109/ICDCS.2009.9
  • Filename
    5158418