InterestFence: Countering Interest Flooding Attacks by Using Hash-Based Security Labels.

Jiaqing Dong,Kai Wang,Yongqiang Lyu,Libo Jiao,Hao Yin
DOI: https://doi.org/10.1007/978-3-030-05063-4_39
2018-01-01
Abstract:Interest Flooding Attack (IFA) has been one of the biggest threats for the Named Data Networking (NDN) paradigm, while it is very easy to launch but very difficult to mitigate. In this paper, we propose the InterestFence, which is a simple, direct, lightweight yet efficient IFA countermeasure, and the first one to achieve fast detection meanwhile accurate and efficient attacking traffic filtering without harming any legitimate Interests. InterestFence detects IFA based on content servers rather than routers to guarantee accurate detection. All content items with the same prefix within a content server have a hash-based security label (HSL) to claim their existence, and a HSL verification method is securely transmitted to related routers to help filtering and cleaning IFA traffic in transit networks accurately and efficiently. Performance analysis demonstrates the effectiveness of InterestFence on mitigating IFA and its lightweight feature due to the limited overhead involved.
What problem does this paper attempt to address?