AccFlow: Defending Against the Low-Rate TCP DoS Attack in Wireless Sensor Networks

by   Yuan Cao, et al.

Because of the open nature of the Wireless Sensor Networks (WSN), the Denial of the Service (DoS) becomes one of the most serious threats to the stability of the resourceconstrained sensor nodes. In this paper, we develop AccFlow which is an incrementally deployable Software-Defined Networking based protocol that is able to serve as a countermeasure against the low-rate TCP DoS attack. The main idea of AccFlow is to make the attacking flows accountable for the congestion by dropping their packets according to their loss rates. The larger their loss rates, the more aggressively AccFlow drops their packets. Through extensive simulations, we demonstrate that AccFlow can effectively defend against the low-rate TCP DoS attack even if attackers vary their strategies by attacking at different scales and data rates. Furthermore, while AccFlow is designed to solve the low-rate TCP DoS attack, we demonstrate that AccFlow can also effectively defend against general DoS attacks which do not rely on the TCP retransmission timeout mechanism but cause denial of service to legitimate users by consistently exhausting the network resources. Finally, we consider the scalability of AccFlow and its deployment in real networks.


Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks

Software-defined networking (SDN) is a promising technology to overcome ...

A Survey of Distributed Denial of Service Attacks and Defenses

A distributed denial-of-service (DDoS) attack is an attack wherein multi...

The impact of copycat attack on RPL based 6LoWPAN networks in Internet of Things

IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) is the stan...

Centralized and Distributed Intrusion Detection for Resource Constrained Wireless SDN Networks

Software-defined networking (SDN) was devised to simplify network manage...

Men-in-the-Middle Attack Simulation on Low Energy Wireless Devices using Software Define Radio

The article presents a method of organizing men-in-the-middle attack and...

On the Feasibility and Enhancement of the Tuple Space Explosion Attack against Open vSwitch

Being a crucial part of networked systems, packet classification has to ...

An Effective Privacy-Preserving Data Coding in Peer-To-Peer Network

Coding Opportunistically (COPE) is a simple but very effective data codi...

Please sign up or login with your details

Forgot password? Click here to reset