The search functionality is under construction.

IEICE TRANSACTIONS on Fundamentals

Proactive Defense Mechanism against IP Spoofing Traffic on a NEMO Environment

Mihui KIM, Kijoon CHAE

  • Full Text Views

    0

  • Cite this

Summary :

The boundary of a distributed denial of service (DDoS) attack, one of the most threatening attacks in a wired network, now extends to wireless mobile networks, following the appearance of a DDoS attack tool targeted at mobile phones. However, the existing defense mechanisms against such attacks in a wired network are not effective in a wireless mobile network, because of differences in their characteristics such as the mobile possibility of attack agents. In this paper, we propose a proactive defense mechanism against IP spoofing traffic for mobile networks. IP spoofing is one of the features of a DDoS attack against which it is most difficult to defend. Among the various mobile networks, we focus on the Network Mobility standard that is being established by the NEMO Working Group in the IETF. Our defense consists of following five processes: speedy detection, filtering of attack packets, identification of attack agents, isolation of attack agents, and notification to neighboring routers. We simulated and analyzed the effects on normal traffic of moving attack agents, and the results of applying our defense to a mobile network. Our simulation results show that our mechanism provides a robust defense.

Publication
IEICE TRANSACTIONS on Fundamentals Vol.E89-A No.7 pp.1959-1967
Publication Date
2006/07/01
Publicized
Online ISSN
1745-1337
DOI
10.1093/ietfec/e89-a.7.1959
Type of Manuscript
Special Section PAPER (Special Section on Multi-dimensional Mobile Information Networks)
Category

Authors

Keyword