{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/34416"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/34416","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Secure resource management in networks","abstract":"This dissertation reports research conducted in two aspects of secure network resource management: strengthening security by proposing a defense architecture with stronger security property and increasing deployability. In the first part of this dissertation, we reveal a new threat called false feedback attack in wireless networks using channel-aware protocols. Our simulations show that an attacker overclaiming its channel condition is able to completely steal other benign users' service opportunity under a high-efficiency scheduler. A fair scheduler can mitigate this attack but cannot provide high efficiency. We propose a new secure channel estimation scheme to maintain security while achieving high efficiency at the same time. Our analysis and simulations show that our scheme prohibits any incentive for an attacker performing false feedback attack and gives higher throughput than PF scheduler, a representative fair scheduler. In the second part, we present CRAFT, a collusion-resistant DoS (denial of service) defense. CRAFT defends against a colluding receiver who intentionally allows a colluding sender to send excessive traffic. Our basic idea is that a CRAFT router securely emulates TCP operation. Our simulations show that CRAFT guarantees service availability even with colluding attackers. Our prototype system shows the feasibility of CRAFT. In the third part, we present Mirage, a deployable DoS defense. Prior defenses require other network operators to deploy the same defense mechanism. Mirage does not impose this requirement. Our analysis and prototype system show that Mirage does not require other network operators' deployment and is feasible with commodity PCs.","abstract_html":"This dissertation reports research conducted in two aspects of secure network resource management: strengthening security by proposing a defense architecture with stronger security property and increasing deployability. In the first part of this dissertation, we reveal a new threat called false feedback attack in wireless networks using channel-aware protocols. Our simulations show that an attacker overclaiming its channel condition is able to completely steal other benign users&#x27; service opportunity under a high-efficiency scheduler. A fair scheduler can mitigate this attack but cannot provide high efficiency. We propose a new secure channel estimation scheme to maintain security while achieving high efficiency at the same time. Our analysis and simulations show that our scheme prohibits any incentive for an attacker performing false feedback attack and gives higher throughput than PF scheduler, a representative fair scheduler. In the second part, we present CRAFT, a collusion-resistant DoS (denial of service) defense. CRAFT defends against a colluding receiver who intentionally allows a colluding sender to send excessive traffic. Our basic idea is that a CRAFT router securely emulates TCP operation. Our simulations show that CRAFT guarantees service availability even with colluding attackers. Our prototype system shows the feasibility of CRAFT. In the third part, we present Mirage, a deployable DoS defense. Prior defenses require other network operators to deploy the same defense mechanism. Mirage does not impose this requirement. Our analysis and prototype system show that Mirage does not require other network operators&#x27; deployment and is feasible with commodity PCs.","abstract_has_math":false,"creators":["Kim, Dongho"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Hu, Yih-Chun","Caesar, Matthew C.","Kumar, P.R.","Vaidya, Nitin H."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-09-18T21:15:49Z","date_published":"2012-09-18T21:15:49Z","updated_at":"2026-07-22T22:25:31Z","subjects":["Security","Internet","Wireless Network","Denial of service (DoS) defense"],"languages":["en"],"rights":["Copyright 2012 Dongho Kim"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/34416","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Hu, Yih-Chun","Caesar, Matthew C.","Kumar, P.R.","Vaidya, Nitin H."]},{"key":"dc:creator","label":"Author","values":["Kim, Dongho"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2012-09-18T21:15:49Z","2012-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Security","Internet","Wireless Network","Denial of service (DoS) defense"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2012 Dongho Kim"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/34416"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["This dissertation reports research conducted in two aspects of secure network resource management: strengthening security by proposing a defense architecture with stronger security property and increasing deployability. In the first part of this dissertation, we reveal a new threat called false feedback attack in wireless networks using channel-aware protocols. Our simulations show that an attacker overclaiming its channel condition is able to completely steal other benign users' service opportunity under a high-efficiency scheduler. A fair scheduler can mitigate this attack but cannot provide high efficiency. We propose a new secure channel estimation scheme to maintain security while achieving high efficiency at the same time. Our analysis and simulations show that our scheme prohibits any incentive for an attacker performing false feedback attack and gives higher throughput than PF scheduler, a representative fair scheduler. In the second part, we present CRAFT, a collusion-resistant DoS (denial of service) defense. CRAFT defends against a colluding receiver who intentionally allows a colluding sender to send excessive traffic. Our basic idea is that a CRAFT router securely emulates TCP operation. Our simulations show that CRAFT guarantees service availability even with colluding attackers. Our prototype system shows the feasibility of CRAFT. In the third part, we present Mirage, a deployable DoS defense. Prior defenses require other network operators to deploy the same defense mechanism. Mirage does not impose this requirement. Our analysis and prototype system show that Mirage does not require other network operators' deployment and is feasible with commodity PCs.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-05-16T19:29:35Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Kim_Dongho.pdf: 2110140 bytes, checksum: 8f87acd595938d7ec52204313af0a8d1 (MD5)","Made available in DSpace on 2012-09-18T21:15:49Z (GMT). No. of bitstreams: 2 Kim_Dongho.pdf: 2110140 bytes, checksum: 8f87acd595938d7ec52204313af0a8d1 (MD5) license.txt: 4058 bytes, checksum: 04b3a55b7893c85364f85552e55214cc (MD5)"]},{"key":"dc:title","label":"Title","values":["Secure resource management in networks"]}]}],"canonical_facts":{"dc:contributor":["Hu, Yih-Chun","Caesar, Matthew C.","Kumar, P.R.","Vaidya, Nitin H."],"dc:creator":["Kim, Dongho"],"dc:date":["2012-09-18T21:15:49Z","2012-08"],"dc:description":["This dissertation reports research conducted in two aspects of secure network resource management: strengthening security by proposing a defense architecture with stronger security property and increasing deployability. In the first part of this dissertation, we reveal a new threat called false feedback attack in wireless networks using channel-aware protocols. Our simulations show that an attacker overclaiming its channel condition is able to completely steal other benign users' service opportunity under a high-efficiency scheduler. A fair scheduler can mitigate this attack but cannot provide high efficiency. We propose a new secure channel estimation scheme to maintain security while achieving high efficiency at the same time. Our analysis and simulations show that our scheme prohibits any incentive for an attacker performing false feedback attack and gives higher throughput than PF scheduler, a representative fair scheduler. In the second part, we present CRAFT, a collusion-resistant DoS (denial of service) defense. CRAFT defends against a colluding receiver who intentionally allows a colluding sender to send excessive traffic. Our basic idea is that a CRAFT router securely emulates TCP operation. Our simulations show that CRAFT guarantees service availability even with colluding attackers. Our prototype system shows the feasibility of CRAFT. In the third part, we present Mirage, a deployable DoS defense. Prior defenses require other network operators to deploy the same defense mechanism. Mirage does not impose this requirement. Our analysis and prototype system show that Mirage does not require other network operators' deployment and is feasible with commodity PCs.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-05-16T19:29:35Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Kim_Dongho.pdf: 2110140 bytes, checksum: 8f87acd595938d7ec52204313af0a8d1 (MD5)","Made available in DSpace on 2012-09-18T21:15:49Z (GMT). No. of bitstreams: 2 Kim_Dongho.pdf: 2110140 bytes, checksum: 8f87acd595938d7ec52204313af0a8d1 (MD5) license.txt: 4058 bytes, checksum: 04b3a55b7893c85364f85552e55214cc (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/34416"],"dc:language":["en"],"dc:rights":["Copyright 2012 Dongho Kim"],"dc:subject":["Security","Internet","Wireless Network","Denial of service (DoS) defense"],"dc:title":["Secure resource management in networks"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:31Z"}