ASTVA: DDoS-limiting Architecture for Next Generation Internet

被引:0
|
作者
Wei Wei [1 ]
Xia Yingjie [2 ]
Dong Yabo [3 ]
机构
[1] Henan Univ Technol, Coll Informat Sci & Engn, Zhengzhou 450003, Peoples R China
[2] Hangzhou Normal Univ, Hangzhou Inst Serv Engn, Hangzhou 310012, Zhejiang, Peoples R China
[3] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310027, Zhejiang, Peoples R China
关键词
DDoS defense; Architecture; Next Generation Internet; Internet of Things; NETWORK;
D O I
10.4028/www.scientific.net/AMR.542-543.1275
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security is an important consideration in next generation Internet, where Distributed Denial of Service (DDoS) attack is still a serious threat, especially when Internet of Things is taken into account. To defend against DDoS, capability based Traffic Validation Architecture (TVA) is an excellent candidate. However, there are some shortcomings which make it not so practical, e.g., it has large capability overhead and some DoS attacks could escape from it. To overcome these problems, we proposed the autonomic system based architecture: ASTVA, which created and verified capability using autonomic system as the basic defense unit. In ASTVA, two kinds of sub-capabilities were provided and serveral system security levels were given by mixing the two kinds of sub-capabilities; several key parameters were adjusted dynamically to enhance system flexibility; and an anti-shrew function was added to TVA to make it more robust against low-rate DoS attacks. Finally, we gave out several simulation tests and the results show that ASTVA is more robust and flexible than TVA and is more practical to real world security.
引用
收藏
页码:1275 / +
页数:2
相关论文
共 50 条
  • [1] A streaming architecture for next generation Internet
    Dutta, A
    2001 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-10, CONFERENCE RECORD, 2001, : 1303 - 1309
  • [2] Research on next-generation Internet architecture
    Wu, Jian-Ping
    Xu, Ke
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2006, 21 (05) : 723 - 731
  • [3] Service model and architecture for next generation Internet
    Information Network Center, Beijing University of Posts and Telecommunications, Beijing 1000876, China
    Gaojishu Tongxin, 2007, 11 (1101-1106):
  • [4] Research on Next-Generation Internet Architecture
    Jian-Ping Wu
    Ke Xu
    Journal of Computer Science and Technology, 2006, 21 : 723 - 731
  • [5] FlexNGIA: A Flexible Internet Architecture for the Next-Generation Tactile Internet
    Zhani, Mohamed Faten
    ElBakoury, Hesham
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 751 - 795
  • [6] FlexNGIA: A Flexible Internet Architecture for the Next-Generation Tactile Internet
    Mohamed Faten Zhani
    Hesham ElBakoury
    Journal of Network and Systems Management, 2020, 28 : 751 - 795
  • [7] Research and exploration of next-generation internet architecture
    Wu, Jian-Ping
    Wu, Qian
    Xu, Ke
    Jisuanji Xuebao/Chinese Journal of Computers, 2008, 31 (09): : 1536 - 1548
  • [8] A QoS engineering architecture for the Next-Generation-Internet
    Meempat, G
    Kant, L
    7TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS - PROCEEDINGS, 1998, : 599 - 608
  • [9] Security in the Cache and Forward Architecture for the Next Generation Internet
    Hadjichristofi, G. C.
    Hadjicostis, C. N.
    Raychaudhuri, D.
    DISTRIBUTED COMPUTING AND NETWORKING, 2011, 6522 : 328 - +
  • [10] Internet 3.0: Ten problems with current Internet architecture and solutions for the next generation
    Jain, Raj
    MILCOM 2006, VOLS 1-7, 2006, : 2309 - 2317