When statistical multiplexing is used to provide connectivity to a number of client hosts through a high-delay link, the original TCP as well as TCP variants born to improve performance on those links often provide poor performance and sub-optimal QoS properties. To guarantee intra-protocol fairness, inter-protocol friendliness, low queues utilization and optimal throughput in mission-critical scenarios, Congestion Control Middleware Layer (C2ML) has been proposed as a tool for centralized and collaborative resource management. However, C2ML offers only very limited security guarantees. Because emergencies may be natural or man-provoked, in the latter case there may be interest to cut out legitimate users from the communication networks that support disaster recovery operations. In this paper we present Queue Rate Management (QRM), an Active Queue Management scheme able to provide protection from Resource Exhaustion Attacks in scenarios where access to the shared link is controlled by C2ML; the proposed algorithm checks whether a node is exceeding its allowed rate, and consequently decides whether to keep or drop packets coming from that node. We mathematically prove that with QRM the gateway queue size can never exceed the Bandwidth-Delay Product of the channel. Furthermore, we use the ns-3 simulator to compare QRM with CoDel and RED, showing how QRM provides better performance in terms of both throughput and QoS guarantees when employed with C2ML.
|Data di pubblicazione:||2015|
|Titolo:||Towards Emergency Networks Security with Per-Flow Queue Rate Management|
|Autore/i:||Casoni, Maurizio; Grazia, CARLO AUGUSTO; Klapez, Martin; Patriciello, Natale|
|Digital Object Identifier (DOI):||http://dx.doi.org/10.1109/PERCOMW.2015.7134087|
|Nome del convegno:||Fifth IEEE International Workshop on Pervasive Networks for Emergency Management (PerNEM)|
|Luogo del convegno:||St. Louis (U.S.A.)|
|Data del convegno:||23-27 March 2015|
|Citazione:||Towards Emergency Networks Security with Per-Flow Queue Rate Management / Casoni, Maurizio; Grazia, CARLO AUGUSTO; Klapez, Martin; Patriciello, Natale. - ELETTRONICO. - (2015), pp. 493-498. ((Intervento presentato al convegno Fifth IEEE International Workshop on Pervasive Networks for Emergency Management (PerNEM) tenutosi a St. Louis (U.S.A.) nel 23-27 March 2015.|
|Tipologia||Relazione in Atti di Convegno|
File in questo prodotto:
I documenti presenti in Iris Unimore sono rilasciati con licenza Creative Commons Attribuzione - Non commerciale - Non opere derivate 3.0 Italia, salvo diversa indicazione.
In caso di violazione di copyright, contattare Supporto Iris