{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/29832"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/29832","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Assuring network service with bandwidth and integrity based fairness","abstract":"During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.","abstract_html":"During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.","abstract_has_math":false,"creators":["Khan, Fariba"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A.","Caesar, Matthew C.","Khanna, Sanjeev","Nahrstedt, Klara"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-02-06T20:20:33Z","date_published":"2012-02-06T20:20:33Z","updated_at":"2026-07-22T22:25:29Z","subjects":["Distributed Denial of Service (DDoS)","Incentives","Integrity","Fairness","Spoofing Index"],"languages":["en"],"rights":["Copyright 2011 Fariba Khan"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/29832","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A.","Caesar, Matthew C.","Khanna, Sanjeev","Nahrstedt, Klara"]},{"key":"dc:creator","label":"Author","values":["Khan, Fariba"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2012-02-06T20:20:33Z","2011-12"]},{"key":"dc:type","label":"Dc Type","values":["Dissertation / Thesis","text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Distributed Denial of Service (DDoS)","Incentives","Integrity","Fairness","Spoofing Index"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2011 Fariba Khan"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/29832"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2011-11-26T19:22:54Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5) Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5)","Made available in DSpace on 2012-02-06T20:20:33Z (GMT). No. of bitstreams: 3 Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5) Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5) license.txt: 4059 bytes, checksum: a3f79d0f6cf6a70babad8b2d2b568c41 (MD5)"]},{"key":"dc:title","label":"Title","values":["Assuring network service with bandwidth and integrity based fairness"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A.","Caesar, Matthew C.","Khanna, Sanjeev","Nahrstedt, Klara"],"dc:creator":["Khan, Fariba"],"dc:date":["2012-02-06T20:20:33Z","2011-12"],"dc:description":["During an Internet distributed denial-of-service (DDoS) attack, attackers pose as a superpower overloading bandwidth and services that otherwise would have been lightly used by genuine users. These legitimate users send few packets and occasionally back-off and fail while competing for resources. The Internet architecture provides only modest support for verifying the true origin of a packet or intention of a sender. This makes identification and filtering of attack traffic difficult. DDoS attacks could be limited greatly if there were a way to fairly distribute the resources among the parties despite limited origin integrity. In our work, we propose two methods for achieving fairness despite no or partial implementation for integrity verification. Adaptive Selective Verification (ASV) provides legitimate clients service despite large but bounded attack rates without any integrity infrastructure. ASV can be implemented, without the cooperation of the core routers, by slight modification of the client and server applications. The other system is Integrity Based Queuing (IBQ). In this work, we expect that integrity will not be perfect, but observe that even an imperfect implementation can improve the effectiveness of queuing when parities with better a integrity level are incentivized. ASV and IBQ together create a mechanism for incentives, infrastructure and independence for network service assurance. ASV is shown to be efficient in terms of bandwidth consumption using network simulations. It differs from previously-investigated adaptive mechanisms for bandwidth based payment by requiring very limited state on server. Our study of IBQ includes proof of direct relationship of integrity to service, a network simulation for comparative study, simulation with real attack traffic and security analysis. Our network assurance architecture provides a synergistic approach for defending against DDoS attacks. With moderate infrastructure support, IBQ can be an architecture to provide graded source validation on the Internet. Clients that do not have the support from the ISP, use their spare bandwidth with ASV for service.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2011-11-26T19:22:54Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5) Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5)","Made available in DSpace on 2012-02-06T20:20:33Z (GMT). No. of bitstreams: 3 Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5) Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5) license.txt: 4059 bytes, checksum: a3f79d0f6cf6a70babad8b2d2b568c41 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/29832"],"dc:language":["en"],"dc:rights":["Copyright 2011 Fariba Khan"],"dc:subject":["Distributed Denial of Service (DDoS)","Incentives","Integrity","Fairness","Spoofing Index"],"dc:title":["Assuring network service with bandwidth and integrity based fairness"],"dc:type":["Dissertation / Thesis","text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:29Z"}