谷歌浏览器插件
订阅小程序
在清言上使用

Attackers, Packets, and Puzzles: On Denial-of-Service Prevention in Local Area Networks

Attackers, Packets, and Puzzles: On Denial-of-Service Prevention in Local Area Networks(2012)

引用 22|浏览20
暂无评分
摘要
We tackle the problem of securing communication in Local Area Networks (LANs) and making it resistant against Denial-of-Service (DoS) attacks. Our first contribution is the Cryptographic Link Layer (CLL) - a comprehensive security protocol that provides authentication and confidentiality between neighboring hosts from the link layer upwards. Verifying digital signatures in the handshake phase of CLL is an expensive task compared to symmetric-key operations. Thus, it may become a target for new DoS attacks. We introduce a countermeasure against DoS flooding attacks on public-key handshakes in LANs, called counter-flooding. A known approach against DoS attacks in the Internet are client puzzles. However, existing client puzzle schemes have drawbacks when being applied in LANs. We propose a novel, non-parallelizable scheme for client puzzles based on the computation of square roots modulo a prime. By introducing a secure client puzzle architecture we provide a solid basis to safely employ non-interactive client puzzles. In our final contribution, we pursue the idea of cryptographic puzzles beyond DoS protection and propose an offline submission protocol based on RSA time-lock puzzles.
更多
查看译文
关键词
client puzzle,DoS attack,DoS flooding attack,DoS protection,existing client puzzle scheme,new DoS attack,non-interactive client puzzle,secure client puzzle architecture,RSA time-lock puzzle,comprehensive security protocol,Denial-of-Service Prevention,Local Area Networks
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要