Journal on Communications ›› 2013, Vol. 34 ›› Issue (9): 132-141.doi: 10.3969/j.issn.1000-436x.2013.09.016

• Academic paper • Previous Articles     Next Articles

AS-level model for restraining DoS attacks

Xian-liang JIANG1,3,Guang JIN2,3,Jian-gang YANG1,Jia-ming HE2,3   

  1. 1 CollegeofComputer Science and Technology,Zhejiang University,Hangzhou310027,China
    2 Collegeof Information Science and Engineering,Ningbo University,Ningbo 315211,China
    3 Mobile Network Application Technology Key Laboratory of Zhejiang Province,Ningbo 315211,China
  • Online:2013-09-25 Published:2017-07-05
  • Supported by:
    This Research was Supported in Part by Major Projects of National Science and Technology;Zhejiang Provincial Technology Innovation Team;The Natural Science Foundation of Zhejiang Province;The Natural Science Foundation of Ningbo;Ningbo Municipal Technology Innovation Team

Abstract:

Combined with the next generation security architecture,a novel AS-level defense scheme was proposed to restrain DoS attacks in the Internet.And the deficiencies of previous capability schemes were analyzed in detail,especially on requesting/withdrawing authorization of capabilities.The scheme takes account of a congestion feedback mechanism,a combination with multi-level active queue management,and the credit computation.Then a further analysis on the scheme’s effectiveness was presented.Several experiments with NS2 and CAIDA’s topology datasets were performed to evaluate the authorizing time and traffic,the average requesting time and common file transfer time of different schemes.The results show that this scheme can effectively reduce the average requesting time of capabilities,improve common file transfer efficiency,and enhance the feasibility and robustness.

Key words: network security, denial-of-service attack, autonomous system, network congestion, capabilities

No Suggested Reading articles found!