Modeling NDN PIT to analyze the limits of timeout on the effectiveness of flooding attacks

Flávio de Q. Guimarães, Antônio A. de A. Rocha, Célio V. N. Albuquerque, Igor Ribeiro · 2016

Named Data Networking (NDN) is one of the promising proposals of Future Internet Architectures (FIAs). Similarly to most of the other FIA proposals, NDN promises better performance and resilience against current Internet attacks. However, NDN's resilience has not been largely analyzed yet, in special the flooding attacks that exploit the content request and distribution data structure in NDN routers (called Pending Interest Table - PIT). This paper focuses on analyzing this type of denial of service (DoS) attack. It proposes an analytical model that helps to understand the conditions that make the architecture more or less susceptible to this threat. Evaluation shows that the model is useful to analyze the circumstances in which the PIT is more vulnerable to flooding attack. An extension of the model is used to formulate an optimization function which maximizes the system throughput, minimizing the effects of a DoS attack.

Read the paper · More papers on PaperTik