Mitigation of DHCP starvation attack

被引:21
作者
Mukhtar, Husameldin [1 ]
Salah, Khaled [1 ]
Iraqi, Youssef [1 ]
机构
[1] Khalifa Univ Sci Technol & Res KUSTAR, Al Ain, U Arab Emirates
关键词
LAYER; LINK;
D O I
10.1016/j.compeleceng.2012.06.005
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
DHCP starvation attack is an attack that targets DHCP servers whereby forged DHCP requests are crafted by an attacker with the intent of exhausting all available IF addresses that can be allocated by the DHCP server. Under this attack, legitimate network users can be denied service. In this paper, we describe the seriousness of the attack and survey and evaluate existing solutions designed to mitigate such an attack. In addition, we propose a novel mitigation solution. Our solution overcomes the limitations of existing solutions in terms of performance, effectiveness, and flexibility. Our solution is based on dynamic fair allocation of IF addresses and is suitable for unshared and shared (wireless) access networks. We study and analyze the proposed mitigation technique through numerical examples and simulations. Furthermore, simulation results show that our proposed solution is far superior in mitigating DHCP starvation attack when compared to other existing techniques such as fixed allocation and DHCP request rate detection. (c) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1115 / 1128
页数:14
相关论文
共 30 条
  • [1] Alabady S.A.J., 2008, P 2008 3 INT C INFOR, P1, DOI [DOI 10.1109/ICTTA.2008.4530276, 10.1109/ICTTA.2008.4530276]
  • [2] Altunbasak H, 2004, CONF LOCAL COMPUT NE, P417
  • [3] [Anonymous], SAFE LAYER 2 SECURIT
  • [4] [Anonymous], SIMEVENTS US GUID
  • [5] [Anonymous], 37 MIT
  • [6] [Anonymous], 2001, 3118 RFC
  • [7] [Anonymous], 2011 IJCAI WORKSH IN
  • [8] [Anonymous], 2008, P IEEE INFOCOM 2008
  • [9] [Anonymous], COMP ENG TECHN ICCET
  • [10] [Anonymous], AUTHENTICATION METHO