Enhancing Internet Robustness against Malicious Flows Using RECHOKe

Visvasuresh Victor Govindaswamy, Gergely V. Zaruba, Govindasamy Balasekaran · International Journal of Networks and Communications · 2015

xCHOKe, CHOKe and RED-PD are some of the schemes that have been proposed to control malicious flows in IP networks. Both xCHOKe and CHOKe use CHOKe hits while RED-PD uses RED drops in identifying these flows. In this paper, we are proposing a new scheme called RECHOKe (REpeatedly CHOose and Keep for responsive flows, REpeatedly CHOose and Kill for unresponsive flows) that can be used for detection, control and punishment of these malicious flows. It does this by combining the techniques used by CHOKe, xCHOKe and RED-PD. The difference is, unlike in xCHOKe and CHOKe, RECHOKe does not drop packets during CHOKe hits, thereby eliminating the complexity of dropping or marking randomly selected packets already queued. By using both the CHOKe hit and CHOKe-RED drop histories, we show using ns2 1) that RECHOKe is able to detect, control and punish these flows more accurately, when compared to RED, CHOKe and xCHOKe while providing more protection for TCP-friendly flows, 2) how accurate these histories are, when used in conjunction, in identifying malicious flows and 3) the unreliability of RED, CHOKe and xCHOKe in affecting TCP-friendly flows. Other similar proposed schemes either did not perform as well or incur too much overhead.

Read the paper · More papers on PaperTik