ACM Home Page
Please provide us with feedback. Feedback
Simulation for intrusion-resilient, DDoS-resistant authentication system (IDAS)
Full text PdfPdf (417 KB)
Source
Spring Simulation Multiconference archive
Proceedings of the 2008 Spring simulation multiconference table of contents
Ottawa, Canada
SESSION: 2008 simulation software security symposium (SSSS'08) table of contents
Pages 844-851  
Year of Publication: 2008
ISBN:1-56555-319-5
Authors
Chwan Hwa "John" Wu  Auburn Univeristy, AL
Tong Liu  Auburn Univeristy, AL
Sponsors
SIGSIM: ACM Special Interest Group on Simulation and Modeling
(SCS) : The Society for Modeling and Simulation International
Publisher
Bibliometrics
Downloads (6 Weeks): 7,   Downloads (12 Months): 107,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Review this Article  

ABSTRACT

SSL (Secure Sockets Layer) protocol and IPSec (Internet Protocol Security) are widely used for identity authentication and communication protection. However, both protocols suffer from intrusion and single-point of compromising as well as DDoS (distributed denial of service) attacks. An innovative Intrusion-Resilient, DDoS-Resistant Authentication System (IDAS) System is proposed to achieve the following goals:

(1) An intrusion-resilient authentication protocol will be able to protect credential information by distributing shared secret to multiple computers and thus eliminates the single point of compromising.

(2) This protocol can readily detect the use of partial credential as a user/computer and indicate which part of secret is exposed; consequently, the compromised computer can be recovered.

(3) Even when an insider compromised all related servers, the credential is only valid for a short period of time and will be self healed in next period.

(4) A DDoS resistant protocol must be stateless and efficient as well as stop botnet attacks and "low and slow" attacks.

(5) This authentication protocol only takes a single round trip time, which is faster than any other authentication protocols and is important to the performance of critical applications in a multi-continent network.

It is difficult to prove the capabilities of IDAS by actually implementing a full scale botnet due to financial constraint. Instead, simulation results are reported in this paper to show that this IDAS protocol can resist DDoS attacks even when thousands of attackers, which is about the same size as the current botnet, are bombarding it. A user will not even sense the extra delay due to the DDoS attacks; thus, the collateral damage is eliminated.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
 
3
Song, D. dsniff. {Online} http://naughty.monkey.org/~dugsong/dsniff/
4
5
6
7
 
8
9
10
11
12
 
13
14
 
15
Y. Shiraishi, Y. Fukuta, and M. Moril, "Port randomized VPN by mobile codes," in Proceedings from First IEEE Consumer Communications and Networking Conference, 2004, pp. 671--673.
16
 
17
 
18
M. Long, and C.-H. Wu, "Energy-efficient and intrusion-resilient authentication for ubiquitous access to factory floor information," IEEE Transactions on Industrial Informatics, vol. 2, issue 1, pp. 40--47, Feb. 2006.
19
 
20

Collaborative Colleagues:
Chwan Hwa "John" Wu: colleagues
Tong Liu: colleagues