A Reconstruction Forest-Based Interest Flooding Attack Detection Method in Named Data Networking
Guanglin Xing, Xiaoqi Li, Rui Hou · 2024
Named data networking (NDN) is considered one of the most viable architectures in information-centric networking (ICN) and a promising candidate for future internet architecture. However, interest flooding attacks (IFAs) in NDN can seriously threaten the security of a network. An IFA is one type of distributed denial of service (DDoS) attack in NDN. IFA attackers consume the bandwidth, router cache and computing resources of a network by introducing a large number of malicious interest packets into the network, and the router's ability to receive and forward packets is reduced or can even fail, thus causing the network to crash. Therefore, a highly efficient detection method is urgently needed to mitigate the harmfulness of IFAs. However, existing IFA detection methods have limitations in terms of detection accuracy and anti-interference capability, especially for traffic fluctuations that may produce false positives, thus reducing IFA detection efficiency. In this paper, a novel IFA detection method named the reconstruction forest-based detection method (RFDM) is proposed to achieve highly efficient attack detection and traffic fluctuation determination. A RecForest is used to calculate the reconstruction error through the reconstruction process, detect malicious interest packets, and mitigate IFAs by restricting malicious interest packet forwarding. The simulation results show that the RFDM outperforms other typical IFA detection methods in terms of detection speed, accuracy, and resistance to network fluctuations.