Controller Based Detection Scheme of Interest Flooding Attack in Named Data Networking
Gubei Yin, Junhua Tang, Futai Zou, Yue Wu, Jianhua Li · 2019
Information-centric networking (ICN), which is believed to be one of the most promising technologies in the next-generation network, has drawn lots of attention from both academia and industry. While ICN solves many problems of the TCP/IP architecture, new security issues arise. The interest flooding attack is one of them. In this paper, we discuss the influences of this type of attack in Named Data Networking (NDN) and propose a novel detection and mitigation scheme. In this scheme, a controller is introduced in an NDN domain to collect routing and forwarding statistics from routers. These statistics are then analyzed by the controller to detect interest flooding attack as well as trace the adversaries and malicious prefixes. Simulation experiments are conducted using ndnSIM, and the results demonstrate that the proposed scheme is both effective and efficient.