Degradation attacks on Passive Optical Networks

Sanda Drakulic, M. Tornatore, G. Verticale
{"title":"Degradation attacks on Passive Optical Networks","authors":"Sanda Drakulic, M. Tornatore, G. Verticale","doi":"10.1109/ONDM.2012.6210184","DOIUrl":null,"url":null,"abstract":"Passive Optical Networks (PONs) are a promising candidate to solve the last-mile problem in access networks. By using optical fibers, PONs can offer to the subscribers higher capacity than other traditional access technologies, such as xDSL or Cable-TV, at a lower cost than FTTx solutions. As for any other access-network technology, security is a very important issue. PONs have very specific security requirements because (i) the downstream transmission channel is inherently broadcast, and (ii) malicious transmissions in the upstream channel can not be easily detected and prevented. This paper shows that malicious upstream transmissions can be used to conduct very intrusive degradation attacks upon the upstream traffic and quantifies the decrement of the upstream throughput over a PON under different scenarios of degradation attack. Further, the paper considers how the effect of a degradation attack carried on at the physical layer is greatly amplified by the TCP congestion control algorithm resulting in a strong degradation with little effort by the attacker. The attacker could then exploit bandwidth sharing mechanisms to gain an unfair amount of bandwidth. We also propose a possible mitigation strategy that pinpoints the attacker and re-establishes fairness in terms of throughput per ONU.","PeriodicalId":151401,"journal":{"name":"2012 16th International Conference on Optical Network Design and Modelling (ONDM)","volume":"158 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-04-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 16th International Conference on Optical Network Design and Modelling (ONDM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ONDM.2012.6210184","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

Abstract

Passive Optical Networks (PONs) are a promising candidate to solve the last-mile problem in access networks. By using optical fibers, PONs can offer to the subscribers higher capacity than other traditional access technologies, such as xDSL or Cable-TV, at a lower cost than FTTx solutions. As for any other access-network technology, security is a very important issue. PONs have very specific security requirements because (i) the downstream transmission channel is inherently broadcast, and (ii) malicious transmissions in the upstream channel can not be easily detected and prevented. This paper shows that malicious upstream transmissions can be used to conduct very intrusive degradation attacks upon the upstream traffic and quantifies the decrement of the upstream throughput over a PON under different scenarios of degradation attack. Further, the paper considers how the effect of a degradation attack carried on at the physical layer is greatly amplified by the TCP congestion control algorithm resulting in a strong degradation with little effort by the attacker. The attacker could then exploit bandwidth sharing mechanisms to gain an unfair amount of bandwidth. We also propose a possible mitigation strategy that pinpoints the attacker and re-establishes fairness in terms of throughput per ONU.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
无源光网络的退化攻击
无源光网络(PONs)是解决接入网最后一英里问题的一个很有前途的候选者。通过使用光纤,PONs可以为用户提供比其他传统接入技术(如xDSL或Cable-TV)更高的容量,而成本比FTTx解决方案更低。与其他接入网技术一样,安全是一个非常重要的问题。pon具有非常特殊的安全要求,因为(i)下游传输通道本身就是广播的,(ii)上游通道中的恶意传输不容易被检测和阻止。本文证明了恶意上游传输可以对上游流量进行侵入性很强的降级攻击,并量化了在不同降级攻击场景下PON上游吞吐量的衰减。此外,本文还考虑了在物理层进行的降级攻击的影响如何被TCP拥塞控制算法极大地放大,从而导致攻击者只需付出很少的努力就能实现强降级。然后攻击者可以利用带宽共享机制来获得不公平的带宽。我们还提出了一种可能的缓解策略,该策略可以精确定位攻击者并根据每个ONU的吞吐量重新建立公平性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analytical model for anycast service provisioning in data center interconnections Routing in dynamic future flexi-grid optical networks Fair scheduling of dynamically provisioned WDM connections with differentiated signal quality Software/hardware defined network (SHINE): A novel adaptive optical network framework for future internet The role of network topology on the energy efficiency of IP-over-WDM architectures
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1