J4 ›› 2012, Vol. 34 ›› Issue (11): 14-20.
• 论文 • Previous Articles Next Articles
ZHANG Honghao,WANG Jinsong,LIU Tao
Received:
Revised:
Online:
Published:
Abstract:
An antiDoS (Denial of Service) mechanism called LMCM (Lightweight Multilevel Capabilities Mechanism) for next generation Internet is proposed. The LMCM distinguishes the malicious users and the benign users through their behaviors and adopts lightweight validation mechanism to avoid heavyweight operations in the core network. It improves data transfer efficiency but not lowers the overall security, meeting different security requirements. In order to defend DoC (DenialofCapability) attacks caused by the capabilities and guarantee fairly sharing the network resources, the LMCM adopts a hierarchical queue management mechanism. Furthermore, the LMCM improves the flow control mechanism to defend other complicated attack which cannot be defended in TVA(Traffic Validation Architecture) and makes up for the shortcomings and inadequacies of the TVA. In order to get convincing comparative results, we choose some representative topologies in the dataset of the CAIDA (Cooperative Association for Internet Data) as our experiment topologies. Simulation results in dissimilar scenarios indicate that the LMCM is conducive to improving the data transfer efficiency and enhancing the scalability of defense system compared with the TVA.
Key words: next generation Internet;network security;distributed denial of service;traffic validation architecture
ZHANG Honghao,WANG Jinsong,LIU Tao. A Lightweight MultiLevel Capabilities Mechanism for Next Generation Internet[J]. J4, 2012, 34(11): 14-20.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2012/V34/I11/14