110 likes | 274 Views
A Study on Survivability of Mobile Network Nodes in the Network Mobility. Sang Young Lee, Jin Seok Yang, Dong Soo Kim and Tai Myoung Chung Internet Management Technology Lab. Dept. for Electronics and Computer Engineering Sungkyunkwan University Email : sylee@imtl.skku.ac.kr
E N D
A Study on Survivability of Mobile Network Nodes in the Network Mobility Sang Young Lee, Jin Seok Yang, Dong Soo Kim and Tai Myoung Chung Internet Management Technology Lab. Dept. for Electronics and Computer Engineering Sungkyunkwan University Email : sylee@imtl.skku.ac.kr http://imtl.skku.ac.kr Tel. : +82-31-290-7222
[Source : krNIC, NUA, cert/cc Inc.] Introduction • Increase network host & user, then increase incidents
CN Internet AR AR home link visited link MR egress interface MR ingress interface single- link NEMO NEMO link multi-link NEMO Related works • NEMO(Network Mobility) • A Mobile Network is an entire network, moving as a unit, which changes its point of attachment to the Internet. A NEMO may be composed by one or more IP-subnets • IETF NENO WG
Neighborhood 1 Boundary controller ① Intrusion or attacks Discovery coordinator ③ Propagating traceback message Neighborhood 2 Neighborhood 3 Boundary controllers Intrusion detection system ② Sending traceback message Intrusion detection system Boundary controllers Community Related works • CITRA(cooperative intrusion traceback and response architecture) • DARPA, NAI, UC Davis
Related works • Survivability • The capability of a system to fulfill its mission in a timely manner, even in the presence of stresses • Stresses include attacks, failures, accidents, and abnormal loads • DARPA • Survival by defense • Use of redundancy • Monitoring • QoS(Quality of Service) • Self-check • Application adaptation • BBN Technology
Current Issues • NEMO • Single point failure in AR, MR • Low process capability, Battery and Bandwidth of MNNs • QoS & Performance • Security • Confidentiality • Authentication • Authorization • Location Privacy • Access Control : VMN • Survival by Defense - Resource Monitoring • Guarantee QoS
Index Mobile Router w/ RMA Mobile Host w/ RMA Neighborhood 1 AAA Discovery Coordinator HA AR Neighborhood 2 Neighborhood 3 AR Internet AR MR MR AAA AAA Community NCS - Architecture
Repository NCS - Module & Protocol Index Wired networking protocol Resource monitoring info. & AAA protocol COPS LDAP Wireless networking protocol Application RMA RMA Resource Mon. Security Resource Mon. Security AAA Discovery Coordinator OS OS Service APIs Service APIs Transport layer Transport layer Transport layer Service Module Service Module Service Module Resource Mon. Security Transport Resource Mon. Security Transport Resource Mon. Security Transport Service APIs Transport layer Network/DL layer Network/DL layer Network/DL layer Physical layer Physical layer Physical layer Security Systems(IDS, FW, etc.) AR(Access Router) MNNs
Neighborhood 1 AAA Discovery Coordinator HA AR Neighborhood 2 ④ alert & traceback msg Neighborhood 3 AR Internet AR MR MR ③ sending alert & traceback msg ② See the symptoms ①syn-flood attacks AAA AAA Community NCS - Procedure
Conclusions & Future Works • Advantages • No corruption of service in the AR, MR • Guaranteed QoS, Improved Security in the NCS community • Access control, Authorization for MNNs • Conclusions • Survival by defense-enabling in AR, MR • Prevent some attacks • QoS improvement by resource management • Future works • Need consideration of Multi-homing in NEMO • Minimize performance decrease of MNNs • Formalize a method of symptoms detection