E-CAP: An Extended Capability Based Mechanism to Limit Distributed Denial of Service Attacks
Rajeev Singh, Suman R. Das, Durga Toshniwal, Manoj Kumar Mishra, Ramesh Chander Joshi · 2008
Traffic Validation Architecture (TVA) is a capability based network architecture that tries to limit Distributed Denial of Service Attacks (DDoS). It considers only the victimpsilas approval in the capability granting process. We propose an extension to the approach by involving two new parameters, the bottleneck linkpsilas status and message type, in the capability granting mechanism. Both these parameters are considered at the router after the destination has granted capability to send, to the source. Source is allowed to send the data only if the reply to its request containing capability information is bypassed by the router. The inclusion of parameters at the router helps in removing congestion at the bottleneck link and reduces the effect of colluders. The proposed mechanism utilizes the TVA Architecture