Energy Initiative Energy Initiative
Office of the Provost
Duke University

 HOME > Provost > Energy Initiative    Search Help Login pdf version printable version 

Publications [#236669] of Bruce Maggs

Journal articles or Book chapters PUBLISHED

  1. Parno, B; Wendlandt, D; Shi, E; Perrig, A; Maggs, B; Hu, YC, Portcullis: Protecting connection setup from denial-of-capability attacks, Computer Communication Review, vol. 37 no. 4 (October, 2007), pp. 289-300, Association for Computing Machinery (ACM), ISSN 0146-4833 [doi]
    (last updated on 2024/03/28)

    Abstract:
    Systems using capabilities to provide preferential service to selected flows have been proposed as a defense against large-scale network denial-of-service attacks. While these systems offer strong protection for established network flows, the Denial-of-Capability (DoC) attack, which prevents new capability-setup packets from reaching the destination, limits the value of these systems. Portcullis mitigates DoC attacks by allocating scarce link bandwidth for connection establishment packets based on per-computation fairness. We prove that a legitimate sender can establish a capability with high probability regardless of an attacker's resources or strategy and that no system can improve on our guarantee. We simulate full and partial deployments of Portcullis on an Internetscale topology to confirm our theoretical results and demonstrate the substantial benefits of using per-computation fairness. Copyright 2007 ACM.


Duke University * Faculty * Staff * Reload * Login