Doctoral thesis (Dissertations and theses)
A multifold approach to address the security issues of stateful forwarding mechanisms in Information-Centric Networks.
Signorello, Salvatore
2018
 

Files


Full Text
versionBiblio-UniLu.pdf
Author postprint (5.58 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Information-Centric Networking; Named-Data Networking; security; Denial of Service; Interest Flooding Attack
Abstract :
[en] Today's Internet dominant usage trends motivate research on more content-oriented future network architectures. Among the emerging future Internet proposals, the promising Information-Centric Networking (ICN) research paradigm aims to redesign the Internet's core protocols to promote a shift in focus from hosts to contents. Among the ICN architectures, the Named-Data Networking (NDN) envisions users' named content requests to be forwarded and recorded by their names in routers along the path from one consumer to 1-or-many sources. The Pending Interest Table (PIT) is the NDN's data-plane component which temporarily records forwarded content requests in routers. On one hand, the PIT stateful mechanism enables properties like requests aggregation, multicast responses delivery and native hop-by-hop control flow. On the other hand, the PIT stateful forwarding behavior can be easily abused by malicious users to mount disruptive distributed denial of service attacks (DDoS), named Interest Flooding Attacks (IFAs). In IFAs, loosely coordinated botnets flood the network with a large amount of hard to satisfy requests with the aim to overload both the network infrastructure and the content producers. Countermeasures against IFA have been proposed since the early attack discovery. However, a fair understanding of the defense mechanisms' real efficacy is missing since those have been tested under simplistic assumptions about the evaluation scenarios. Thus, overall, the IFA security threat still appears easy to launch but hard to mitigate. This dissertation work shapes a better understanding of both the implications of IFAs and the possibilities of improving the state-of-the-art defense mechanisms against these attacks. The contributions of this work include the definition of a more complete and realistic attacker model for IFAs, the design of novel stealthy IFAs built upon the proposed attacker model, a re-assessment of the most-efficient state-of-the-art IFA countermeasures against the novel proposed attacks, the theorization and one concrete design of a novel class of IFA countermeasures to efficiently address the novel stealthy IFAs. Finally, this work also seminally proposes to leverage the latest programmable data-plane technologies to design and test alternative forwarding mechanisms for the NDN which could be less vulnerable to the IFA threat.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Services and Data management research group (SEDAN)
Disciplines :
Computer science
Author, co-author :
Signorello, Salvatore ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Language :
English
Title :
A multifold approach to address the security issues of stateful forwarding mechanisms in Information-Centric Networks.
Defense date :
21 June 2018
Number of pages :
140
Institution :
University of Luxembourg, Luxembourg, Luxembourg
University of Lorraine, Nancy, France
Degree :
Docteur en Informatique
Promotor :
State, Radu  
Festor, Olivier
President :
Rodošek, Gabrijela
Jury member :
Engel, Thomas 
Palattella, Maria Rita
François, Jérôme
Laurent, Maryline
Focus Area :
Security, Reliability and Trust
FnR Project :
FNR6450335 - Id-based Secure Communications System For Unified Access In Iot, 2013 (01/04/2014-31/03/2017) - Thomas Engel
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 29 August 2018

Statistics


Number of views
135 (8 by Unilu)
Number of downloads
300 (8 by Unilu)

Bibliography


Similar publications



Contact ORBilu