Interest packet flooding attack detection system based on path aggregation in NDN network

A flood attack and detection system technology, applied in transmission systems, digital transmission systems, data exchange networks, etc., can solve problems affecting the normal operation of routing nodes, and achieve the effects of facilitating global optimization, enhancing sensitivity, and improving detection speed

Active Publication Date: 2020-10-16
SHANGHAI JIAO TONG UNIV
View PDF13 Cites 8 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

At this time, each interest packet will be forwarded to the producer, and the producer will return a corresponding NACK interest packet for each interest packet, which is more likely to affect the normal operation of the routing node

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Interest packet flooding attack detection system based on path aggregation in NDN network
  • Interest packet flooding attack detection system based on path aggregation in NDN network
  • Interest packet flooding attack detection system based on path aggregation in NDN network

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0040] The following describes several preferred embodiments of the present invention with reference to the accompanying drawings, so as to make the technical content clearer and easier to understand. The present invention can be embodied in many different forms of embodiments, and the protection scope of the present invention is not limited to the embodiments mentioned herein.

[0041] In the drawings, components with the same structure are denoted by the same numerals, and components with similar structures or functions are denoted by similar numerals. The size and thickness of each component shown in the drawings are shown arbitrarily, and the present invention does not limit the size and thickness of each component. In order to make the illustration clearer, the thickness of parts is appropriately exaggerated in some places in the drawings.

[0042] The invention proposes a path aggregation-based interest packet flooding attack detection system. The NDN routing node judg...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses an interest packet flooding attack detection system based on path aggregation in an NDN network, and relates to the field of next-generation Internet architecture and network security. The system comprises a central controller, an NDN router, a content request node and a content providing node. When the content request node needs a certain piece of content, the required content name is placed in the interest packet and sent to the NDN router; the NDN router decides to provide the content to the request node or forward the interest packet according to the locally cachedcontent; when receiving the interest packet, the content providing node puts the requested content in the data packet and sends the data packet back to the request node; the central controller calculates and issues a routing table to the NDN router through a path aggregation and load balancing algorithm; and the NDN router judges whether an interest packet flooding attack is encountered or not according to three indexes of the interest packet satisfaction rate, the request interest table size and the negative response number of each port. According to the invention, the detection speed of theinterest packet flooding attack is obviously improved, and the sensitivity of interest packet flooding attack detection is enhanced.

Description

technical field [0001] The invention relates to the next-generation Internet architecture and the field of network security, in particular to an interest packet flood attack detection system based on path aggregation in an NDN network. Background technique [0002] Information Centric Network (ICN) is one of the important research directions of future network architecture, aiming to support efficient and scalable content acquisition, device mobility and content security mechanism from the architecture level. The basic design concept of ICN is to abandon the transmission protocol architecture based on IP addresses and adopt the transmission protocol architecture centered on the name of information. Simply put, each piece of content is marked with a unique name, which becomes network information; the network can distinguish each piece of information through this name, and the operation of the entire network is driven by the request, routing and transmission of these informatio...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/911
CPCH04L47/70H04L47/827H04L63/1416H04L63/1441
Inventor 唐俊华王杰李婧松林祥李建华
Owner SHANGHAI JIAO TONG UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products