Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures

The current state of security and availability of the Internet is far from being commensurate with its importance. The number and strength of DDoS attacks conducted at the network layer have been steadily increasing. However, the single path (SP) routing used in today’s Internet lacks a mitigation s...

Full description

Bibliographic Details
Main Authors: Hyok An, Yoonjong Na, Heejo Lee, Adrian Perrig
Format: Article
Language:English
Published: MDPI AG 2021-05-01
Series:Electronics
Subjects:
Online Access:https://www.mdpi.com/2079-9292/10/11/1240
_version_ 1797532966360973312
author Hyok An
Yoonjong Na
Heejo Lee
Adrian Perrig
author_facet Hyok An
Yoonjong Na
Heejo Lee
Adrian Perrig
author_sort Hyok An
collection DOAJ
description The current state of security and availability of the Internet is far from being commensurate with its importance. The number and strength of DDoS attacks conducted at the network layer have been steadily increasing. However, the single path (SP) routing used in today’s Internet lacks a mitigation scheme to rapidly recover from network attacks or link failure. In case of a link failure occurs, it can take several minutes until failover. In contrast, multi-path routing can take advantage of multiple alternative paths and rapidly switch to another working path. According to the level of available path control, we classfy the multi-path routing into two types, first-hop multi-path (FMP) and multi-hop multi-path (MMP) routing. Although FMP routing supported by networks, such as SD-WAN, shows marginal improvements over the current SP routing of the Internet, MMP routing supported by a global Internet architecture provides strong improvement under network attacks and link failure. MMP routing enables changing to alternate paths to mitigate the network problem in other hops, which cannot be controlled by FMP routing. To show this comparison with practical outcome, we evaluate network performance in terms of latency and loss rate to show that MMP routing can mitigate Internet hazards and provide high availability on global networks by 18 participating ASes in six countries. Our evaluation of global networks shows that, if network attacks or failures occur in other autonomous systems (ASes) that FMP routing cannot avoid, it is feasible to deal with such problems by switching to alternative paths by using MMP routing. When the global evaluation is under a transit-link DDoS attack, the loss rates of FMP that pass the transit-link are affected significantly by a transit-link DDoS attack, but the other alternative MMP paths show stable status under the DDoS attack with proper operation.
first_indexed 2024-03-10T11:07:53Z
format Article
id doaj.art-f423058717034ca1b215b0bb89dd2467
institution Directory Open Access Journal
issn 2079-9292
language English
last_indexed 2024-03-10T11:07:53Z
publishDate 2021-05-01
publisher MDPI AG
record_format Article
series Electronics
spelling doaj.art-f423058717034ca1b215b0bb89dd24672023-11-21T21:03:16ZengMDPI AGElectronics2079-92922021-05-011011124010.3390/electronics10111240Resilience Evaluation of Multi-Path Routing against Network Attacks and FailuresHyok An0Yoonjong Na1Heejo Lee2Adrian Perrig3Department of Computer Science and Engineering, Korea University, Seoul 02841, KoreaDepartment of Computer Science and Engineering, Korea University, Seoul 02841, KoreaDepartment of Computer Science and Engineering, Korea University, Seoul 02841, KoreaDepartment of Computer Science, ETH Zurich, 8092 Zurich, SwitzerlandThe current state of security and availability of the Internet is far from being commensurate with its importance. The number and strength of DDoS attacks conducted at the network layer have been steadily increasing. However, the single path (SP) routing used in today’s Internet lacks a mitigation scheme to rapidly recover from network attacks or link failure. In case of a link failure occurs, it can take several minutes until failover. In contrast, multi-path routing can take advantage of multiple alternative paths and rapidly switch to another working path. According to the level of available path control, we classfy the multi-path routing into two types, first-hop multi-path (FMP) and multi-hop multi-path (MMP) routing. Although FMP routing supported by networks, such as SD-WAN, shows marginal improvements over the current SP routing of the Internet, MMP routing supported by a global Internet architecture provides strong improvement under network attacks and link failure. MMP routing enables changing to alternate paths to mitigate the network problem in other hops, which cannot be controlled by FMP routing. To show this comparison with practical outcome, we evaluate network performance in terms of latency and loss rate to show that MMP routing can mitigate Internet hazards and provide high availability on global networks by 18 participating ASes in six countries. Our evaluation of global networks shows that, if network attacks or failures occur in other autonomous systems (ASes) that FMP routing cannot avoid, it is feasible to deal with such problems by switching to alternative paths by using MMP routing. When the global evaluation is under a transit-link DDoS attack, the loss rates of FMP that pass the transit-link are affected significantly by a transit-link DDoS attack, but the other alternative MMP paths show stable status under the DDoS attack with proper operation.https://www.mdpi.com/2079-9292/10/11/1240network securitymulti-path routinghigh availabilityInternet-scale evaluation
spellingShingle Hyok An
Yoonjong Na
Heejo Lee
Adrian Perrig
Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
Electronics
network security
multi-path routing
high availability
Internet-scale evaluation
title Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
title_full Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
title_fullStr Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
title_full_unstemmed Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
title_short Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
title_sort resilience evaluation of multi path routing against network attacks and failures
topic network security
multi-path routing
high availability
Internet-scale evaluation
url https://www.mdpi.com/2079-9292/10/11/1240
work_keys_str_mv AT hyokan resilienceevaluationofmultipathroutingagainstnetworkattacksandfailures
AT yoonjongna resilienceevaluationofmultipathroutingagainstnetworkattacksandfailures
AT heejolee resilienceevaluationofmultipathroutingagainstnetworkattacksandfailures
AT adrianperrig resilienceevaluationofmultipathroutingagainstnetworkattacksandfailures