Proactive Defense Mechanism against IP Spoofing Traffic on a NEMO Environment(<Special Section>Multi-dimensional Mobile Information Networks)
スポンサーリンク
概要
- 論文の詳細を見る
The boundary of a distributed denial of service (DDoS) attack, one of the most threatening attacks in a wired network, now extends to wireless mobile networks, following the appearance of a DDoS attack tool targeted at mobile phones. However, the existing defense mechanisms against such attacks in a wired network are not effective in a wireless mobile network, because of differences in their characteristics such as the mobile possibility of attack agents. In this paper, we propose a proactive defense mechanism against IP spoofing traffic for mobile networks. IP spoofing is one of the features of a DDoS attack against which it is most difficult to defend. Among the various mobile networks, we focus on the Network Mobility standard that is being established by the NEMO Working Group in the IETF. Our defense consists of following five processes: speedy detection, filtering of attack packets, identification of attack agents, isolation of attack agents, and notification to neighboring routers. We simulated and analyzed the effects on normal traffic of moving attack agents, and the results of applying our defense to a mobile network. Our simulation results show that our mechanism provides a robust defense.
- 社団法人電子情報通信学会の論文
- 2006-07-01
著者
-
Chae Kijoon
Dept. Of Computer Science And Engineering Ewha Womans University
-
KIM Mihui
Dept. of Computer Science and Engineering, Ewha Womans University
-
Kim Mihui
Dept. Of Computer Science And Engineering Ewha Womans University