An optimization on requesting and authorization for capabilities architecture

Xianliang Jiang, Guang Jin, Cuixia Ni, Zhijun Xie, Jiangbo Qian · 2011

Distributed Denial of Service (DDoS) attacks have resulted in huge economic loss and great harms to networks. In this paper, we in-depth analyze the shortcomings and lacks of capabilities existing in the router-based Traffic Validation Architecture (TVA) scheme and propose a new scheme with adjustable pre-capabilities and capabilities. It is able to effectively reduce the overall cost of run-time and improve the transmission efficiency in TVA without reducing the overall security of the original scheme. Meanwhile, we specify the concept of credit values that could precisely control the size of authorized capabilities and provide a standard to measure the overall safety of TVA. Furthermore, this paper also gives a new dynamic mechanism to grant capabilities using the proposed credit. The theoretical proof and practical simulation show that our scheme is feasible and effective.

Read the paper · More papers on PaperTik