Poseidon: Mitigating Interest Flooding DDoS Attacks in Named Data Networking
arXiv:1303.4823 · doi:10.1109/LCN.2013.6761300
Abstract
Content-Centric Networking (CCN) is an emerging networking paradigm being considered as a possible replacement for the current IP-based host-centric Internet infrastructure. In CCN, named content becomes a first-class entity. CCN focuses on content distribution, which dominates current Internet traffic and is arguably not well served by IP. Named-Data Networking (NDN) is an example of CCN. NDN is also an active research project under the NSF Future Internet Architectures (FIA) program. FIA emphasizes security and privacy from the outset and by design. To be a viable Internet architecture, NDN must be resilient against current and emerging threats. This paper focuses on distributed denial-of-service (DDoS) attacks; in particular we address interest flooding, an attack that exploits key architectural features of NDN. We show that an adversary with limited resources can implement such attack, having a significant impact on network performance. We then introduce Poseidon: a framework for detecting and mitigating interest flooding attacks. Finally, we report on results of extensive simulations assessing proposed countermeasure.
The IEEE Conference on Local Computer Networks (LCN 2013)
References in corpus (1)
Cited by in corpus (6)
- Backscatter from the Data Plane --- Threats to Stability and Security in Information-Centric Networking
- Elements of Trust in Named-Data Networking
- NAC: Automating Access Control via Named Data
- Interest Flooding Attacks in Named Data Networking: Survey of Existing Solutions, Open Issues, Requirements and Future Directions (Extended version)
- To NACK or not to NACK? Negative Acknowledgments in Information-Centric Networking
- Expect More from the Networking: DDoS Mitigation by FITT in Named Data Networking