The Experts below are selected from a list of 732 Experts worldwide ranked by ideXlab platform

Sung-ryul Kim - One of the best experts on this subject based on the ideXlab platform.

  • sShield: small DDoS defense system using RIP-based traffic deflection in autonomous system
    The Journal of Supercomputing, 2014
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    DDoS (distributed denial of service) attacks have gradually increased and have become more sophisticated. There have been several methods for defending against these attacks. However, because the types and scales of DDoS attacks have been diversified, it has become important to defend against DDoS attacks not only in main networks, but also in small scale networks such as AS (autonomous system). We have designed a DDoS defense system working inside AS without either changing the network structure or modifying the router. For this purpose, we have applied the Shield mechanism, which deals with the location problem in DDoS defense, and utilizes the routing updates protocol called RIP (routing information protocol), a representative protocol of IGP (interior gateway protocol). Moreover, we have also conducted experiments by using simulations to find the optimal number and locations of deployed systems.

  • WorldCIS - Small DDoS defense system using routing deployment method
    2012
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    The defense systems for DDoS(Distributed Denial of Service) attacks are getting more advanced. Where to place the system is a key issue. Shield[1] brings up deployment problem and is made with traffic trapping and traffic black-holing techniques. In this paper, a framework for redirection and filtering that works within an AS(Autonomous System) is proposed, while the Shield works outside an AS. This system allows precise traffic redirection and detection using routing update of RIP, a widely-used IGP(interior gateway protocol). We describe our system using the five DDoS attack scenarios and three-phase modes of operation within an AS.

  • Abstract: DDoS Attack Defense Mechanism using Traffic Deflecting Method in Autonomous System
    2012
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    DDoS (Distributed Denial of Service) attacks remain a major problem for the Internet. Although defense systems are getting more advanced, a remaining key issue is where to place the defense system. A previous work called the Shield, brought up the deployment problem and handles the issue with traffic trapping and traffic black-holing techniques. In this paper, a framework for redirection and filtering that works within an AS (Autonomous System) is proposed, while the Shield works outside an AS. This system allows precise traffic redirection and detection using routing update of RIP, a widelyused IGP (interior gateway protocol). Furthermore, by providing three-phase modes of operation, the framework is designed so that the AS can respond to DDoS attacks in a systematic way.

Ho-seok Kang - One of the best experts on this subject based on the ideXlab platform.

  • sShield: small DDoS defense system using RIP-based traffic deflection in autonomous system
    The Journal of Supercomputing, 2014
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    DDoS (distributed denial of service) attacks have gradually increased and have become more sophisticated. There have been several methods for defending against these attacks. However, because the types and scales of DDoS attacks have been diversified, it has become important to defend against DDoS attacks not only in main networks, but also in small scale networks such as AS (autonomous system). We have designed a DDoS defense system working inside AS without either changing the network structure or modifying the router. For this purpose, we have applied the Shield mechanism, which deals with the location problem in DDoS defense, and utilizes the routing updates protocol called RIP (routing information protocol), a representative protocol of IGP (interior gateway protocol). Moreover, we have also conducted experiments by using simulations to find the optimal number and locations of deployed systems.

  • WorldCIS - Small DDoS defense system using routing deployment method
    2012
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    The defense systems for DDoS(Distributed Denial of Service) attacks are getting more advanced. Where to place the system is a key issue. Shield[1] brings up deployment problem and is made with traffic trapping and traffic black-holing techniques. In this paper, a framework for redirection and filtering that works within an AS(Autonomous System) is proposed, while the Shield works outside an AS. This system allows precise traffic redirection and detection using routing update of RIP, a widely-used IGP(interior gateway protocol). We describe our system using the five DDoS attack scenarios and three-phase modes of operation within an AS.

  • Abstract: DDoS Attack Defense Mechanism using Traffic Deflecting Method in Autonomous System
    2012
    Co-Authors: Ho-seok Kang, Sung-ryul Kim
    Abstract:

    DDoS (Distributed Denial of Service) attacks remain a major problem for the Internet. Although defense systems are getting more advanced, a remaining key issue is where to place the defense system. A previous work called the Shield, brought up the deployment problem and handles the issue with traffic trapping and traffic black-holing techniques. In this paper, a framework for redirection and filtering that works within an AS (Autonomous System) is proposed, while the Shield works outside an AS. This system allows precise traffic redirection and detection using routing update of RIP, a widelyused IGP (interior gateway protocol). Furthermore, by providing three-phase modes of operation, the framework is designed so that the AS can respond to DDoS attacks in a systematic way.

Gregory Mirsky - One of the best experts on this subject based on the ideXlab platform.

Ramon Casellas - One of the best experts on this subject based on the ideXlab platform.

  • Domain Subobjects for Resource ReserVation protocol - Traffic Engineering (RSVP-TE)
    2016
    Co-Authors: Udayasree Palle, Dhruv Dhody, Venugopal Kondreddy, Ramon Casellas
    Abstract:

    The Resource ReserVation protocol - Traffic Engineering (RSVP-TE) specification and the Generalized Multiprotocol Label Switching (GMPLS) extensions to RSVP-TE allow abstract nodes and resources to be explicitly included in a path setup. Further Exclude Routes extensions to RSVP-TE allow abstract nodes and resources to be explicitly excluded in a path setup. This document specifies new subobjects to include or exclude domains during path setup where domain is a collection of network elements within a common sphere of address management or path computational responsibility (such as an interior gateway protocol (IGP) area or an Autonomous System (AS)). Note that the use of AS as an abstract node representing domain is already defined in existing RSVP-TE specefications, albeit with a 2-Byte AS number.

  • Domain Subobjects for the Path Computation Element Communication protocol (PCEP)
    2016
    Co-Authors: Udayasree Palle, Dhruv Dhody, Ramon Casellas
    Abstract:

    The ability to compute shortest constrained Traffic Engineering Label Switched Paths (TE LSPs) in Multiprotocol Label Switching (MPLS) and Generalized MPLS (GMPLS) networks across multiple domains has been identified as a key requirement. In this context, a domain is a collection of network elements within a common sphere of address management or path computational responsibility such as an interior gateway protocol (IGP) area or an Autonomous System (AS). This document specifies a representation and encoding of a domain sequence, which is defined as an ordered sequence of domains traversed to reach the destination domain to be used by Path Computation Elements (PCEs) to compute inter-domain constrained shortest paths across a predetermined sequence of domains. This document also defines new subobjects to be used to encode domain identifiers.

Ulrich Killat - One of the best experts on this subject based on the ideXlab platform.

  • Optimizing IP networks in a hybrid IGP/MPLS environment
    Annales des Télécommunications, 2004
    Co-Authors: Eueung Mulyana, Ulrich Killat
    Abstract:

    In this paper, we consider a traffic engineering ( te ) approach to ip networks in a hybrid igp/mpls environment. Though igp (interior gateway protocol) routing has proven its scalability and reliability, effective traffic engineering has been difficult to achieve in public IP networks because of the limited functional capabilities of conventional ip technologies. mpls (Multi-protocol Label Switching) on the one hand enhances the possibility to engineer traffic on ip networks by allowing explicit routes. But on the other hand it suffers from the scalability ( n -square) problem. Hybrid igp/mpls approaches rely on ip native routing as much as possible and use mpls only if necessary. In this work we propose a novel hybrid traffic engineering method based on genetic algorithms, which can be considered as an offline te approach to handle long or medium-term traffic variations in the range days, weeks or months. In our approach the maximum number of hops an lsp (Label Switched Path) may take and the number of lsps which are applied solely to improve the routing performance, are treated as constraints due to delay considerations and the complexity of management. We apply our method to the German scientific network ( b - win ) for which a traffic matrix is available and also to some other networks with a simple demand model. We will show results comparing this hybrid igp/mpls routing scenario with the result of pure igp routing and that of a full mesh mpls with and without traffic splitting. Dans cet article, nous considérons une approche ingénierie du trafic (traffic engineering, te ) des réseaux ip dans un environnement hybride igp/mpls . Bien que le routage igp (interior gateway protocol) ait prouvé son extensibilité (scalability) et sa fiabilité, l’ingénierie du trafic n’a pas été réalisée efficacement dans les réseaux ip classiques à cause des capacités fonctionnelles limitées d’ ip. mpls (Multi-protocol Label Switching) améliore les possibilités de l’ingénierie du trafic dans les réseaux ip en permettant l’utilisation de routes explicites; par contre il souffre du problème d’extensibilité (N^2). Des approches hybrides igp/mpls se basent sur le routage traditionnel d’ ip autant que possible en utilisant mpls seulement si nécessaire. Dans ce travail, nous proposons une nouvelle méthode d’ingénierie du trafic basée sur l’algorithme génétique. Elle peut être considérée comme une approche offline permettant de gérer les variations de trafic à long ou moyen terme. Dans notre approche, le nombre maximal de sauts qu’un lsp (Label Switched Path) peut prendre et le nombre de lsp utilisés seulement pour améliorer la performance de routage, sont traités comme des contraintes à cause de la complexité de gestion et du délai engendré. Nous appliquons notre méthode au réseau scientifique allemand ( b - win ) pour lequel une matrice de trafic est disponible et également à quelques autres réseaux avec un modèle de simple demande. Nous montrerons les résultats en comparant le scénario du routage hybride igp/mpls à celui du routage igp pur et à celui d’un réseau maillé mpls avec ou sans séparation de flux.