4.1 Article Proceedings Paper

NetFence: Preventing Internet Denial of Service from Inside Out

Journal

ACM SIGCOMM COMPUTER COMMUNICATION REVIEW
Volume 40, Issue 4, Pages 255-266

Publisher

ASSOC COMPUTING MACHINERY
DOI: 10.1145/1851275.1851214

Keywords

Design; Security; Internet; Denial-of-Service; Capability; Congestion Policing

Funding

  1. Direct For Computer & Info Scie & Enginr
  2. Division Of Computer and Network Systems [1040043, 845858] Funding Source: National Science Foundation
  3. Direct For Computer & Info Scie & Enginr
  4. Division Of Computer and Network Systems [0925472] Funding Source: National Science Foundation

Ask authors/readers for more resources

Denial of Service (DoS) attacks frequently happen on the Internet, paralyzing Internet services and causing millions of dollars of financial loss. This work presents NetFence, a scalable DoS-resistant network architecture. NetFence uses a novel mechanism, secure congestion policing feedback, to enable robust congestion policing inside the network. Bottleneck routers update the feedback in packet headers to signal congestion, and access routers use it to police senders' traffic. Targeted DoS victims can use the secure congestion policing feedback as capability tokens to suppress unwanted traffic. When compromised senders and receivers organize into pairs to congest a network link, NetFence provably guarantees a legitimate sender its fair share of network resources without keeping per-host state at the congested link. We use a Linux implementation, ns-2 simulations, and theoretical analysis to show that NetFence is an effective and scalable DoS solution: it reduces the amount of state maintained by a congested router from per-host to at most per-(Autonomous System).

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.1
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available