• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

A Study on a High-Performance Router Architecture with a Distributed and Cooperative Defense Mechanism against Network Attacks

Research Project

Project/Area Number 16300017
Research Category

Grant-in-Aid for Scientific Research (B)

Allocation TypeSingle-year Grants
Section一般
Research Field Computer system/Network
Research InstitutionKyoto Institute of Technology

Principal Investigator

SHIBAYAMA Kiyoshi  Kyoto Institute of Technology, Graduate School of Science and Technology, Professor, 工芸科学研究科, 教授 (70127091)

Co-Investigator(Kenkyū-buntansha) HIRATA Hiroaki  Kyoto Institute of Technology, Graduate School of Science and Technology, Associate Professor, 工芸科学研究科, 助教授 (90273549)
NUMOME Atsushi  Kyoto Institute of Technology, Graduate School of Science and Technology, Research Associate, 工芸科学研究科, 助手 (60335320)
Project Period (FY) 2004 – 2006
Project Status Completed (Fiscal Year 2006)
Budget Amount *help
¥9,400,000 (Direct Cost: ¥9,400,000)
Fiscal Year 2006: ¥2,300,000 (Direct Cost: ¥2,300,000)
Fiscal Year 2005: ¥3,700,000 (Direct Cost: ¥3,700,000)
Fiscal Year 2004: ¥3,400,000 (Direct Cost: ¥3,400,000)
KeywordsRouter / Packet Filtering / DoS Attack / Firewall / Distributed Processing / ネットワークプロセッサ / ルーティング処理 / ネットワークセキュリティ
Research Abstract

We proposed a distributed defending scheme against DDoS (Distributed Denial of Services) attacks and architecture of network routers which are main elements in our scheme.
When a node in the network detects DoS attack packets (such a node may usually be an attack target computer or firewall), it initiates a defending action. The node requests neighbor routers to cut off attack packets, and the neighbor routers begin to block the attack by employing packet filtering technique. In most of commercial routers, even if they are high-end routers, unfortunately, activation of packet filtering can make serious damages on total performance of packet processing. So, when our routers anticipate the remarkable degradation of its total performance by enabling packet filtering, they send copies of the request to the next routers which pass the attack packets. We developed a load balancing mechanism among routers, and this enables efficient block against the attack.
We also enhanced the performance of packet filtering by optimizing the order of filtering rules dynamically, and designed a hardware mechanism to support this.
We verified the effectiveness and efficiency of our scheme by simulation. The result shows that our scheme can successfully nullify the effect of DDoS attacks without obstructing any other network communications.

Report

(4 results)
  • 2006 Annual Research Report   Final Research Report Summary
  • 2005 Annual Research Report
  • 2004 Annual Research Report
  • Research Products

    (10 results)

All 2006 2005 2004

All Journal Article (10 results)

  • [Journal Article] 京都工芸繊維大学における新電子計算機システムについて2006

    • Author(s)
      桝田秀夫
    • Journal Title

      2006PCカンファレンス論文集

      Pages: 4-4

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] New Computer System in Kyoto Institute of Technology2006

    • Author(s)
      Hideo Masuda, et al.
    • Journal Title

      Proceedings of 2006 PC Conference, CIEC

      Pages: 173-176

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] 京都工芸繊維大学における新電子計算機システムについて2006

    • Author(s)
      桝田秀夫
    • Journal Title

      2006 PCカンファレンス論文集

      Pages: 4-4

    • Related Report
      2006 Annual Research Report
  • [Journal Article] ネットワーク認証のための放送範囲可変型イーサネットスイッチ2005

    • Author(s)
      布目 淳
    • Journal Title

      電子情報通信学会論文誌D-I Vol.J88-D-I, No.4

      Pages: 4-4

    • NAID

      10016599057

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] An Ethernet Switch with Two-Level Broadcast Domain for Network Authentication2005

    • Author(s)
      Atsushi Nunome, et al.
    • Journal Title

      The IEICE Transactions on Information and Systems Vol.J88-D-I, No.4

      Pages: 908-911

    • NAID

      10016599057

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] ネットワーク認証のための放送範囲可変型イーサネットスイッチ2005

    • Author(s)
      布目 淳
    • Journal Title

      電子情報通信学会論文誌 J88-D-I・4

      Pages: 4-4

    • NAID

      10016599057

    • Related Report
      2005 Annual Research Report
  • [Journal Article] ネットワーク認証のための放送範囲可変型イーサネットスイッチ2005

    • Author(s)
      布目 淳
    • Journal Title

      電子情報通信学会 論文誌 J-88-D-I・4

      Pages: 4-4

    • NAID

      10016599057

    • Related Report
      2004 Annual Research Report
  • [Journal Article] Performance Evaluation of Dynamic Load Balancing Scheme with Load Prediction Mechanism Using the Load Growing Acceleration for Massively Parallel Computers2004

    • Author(s)
      Atsushi Nunome
    • Journal Title

      Systems and Computers in Japan, Wiley Vol.35, No.11

      Pages: 11-11

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Performance Evaluation of Dynamic Load Balancing Scheme with Load Prediction Mechanism Using the Load Growing Acceleration for Massively Parallel Computers2004

    • Author(s)
      Atsushi Nunome, et al.
    • Journal Title

      Systems and Computers in Japan, Wiley Vol.35, No.11

      Pages: 69-79

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Performance Evaluation of Dynamic Load Balancing Scheme with Load Prediction Mechanism Using the Load Growing Acceleration for Massively Parallel Computers2004

    • Author(s)
      Atushi Nunome
    • Journal Title

      Systems and Computers in Japan, Wiley 36・11

      Pages: 11-11

    • Related Report
      2004 Annual Research Report

URL: 

Published: 2004-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi