Neutralizing interest flooding attacks in Named Data Networks using cryptographic route tokens

Aubrey Alston, Tamer Refaei · 2016

Named Data Networking (NDN) is considered to be a viable candidate to replace the host-centric IP model in the next generation of the Internet. Although NDN is known to be resistant to classical DoS and spoofing attacks, vulnerability to NDN-specific attacks nevertheless arises from the use of stateful routing to satisfy requests (Interests). Prime among these attacks, Interest flooding attacks on Named Data Networks induce denial of service by maliciously occupying memory kept to maintain state of outstanding Interests. While previous work has focused on developing reactive Interest flooding detection and mitigation strategies, we contribute with this an in-packet cryptographic mechanism called the route token which proactively provides named data networks a quantifiable degree of security against Interest flooding without relying on a stateful forwarding plane.

Read the paper · More papers on PaperTik