<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-20T17:07:50Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/29832" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/29832</identifier>
        <datestamp>2023-07-10</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_10761</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_10755</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:contributor>Gunter, Carl A.</dc:contributor>
          <dc:contributor>Caesar, Matthew C.</dc:contributor>
          <dc:contributor>Khanna, Sanjeev</dc:contributor>
          <dc:contributor>Nahrstedt, Klara</dc:contributor>
          <dc:creator>Khan, Fariba</dc:creator>
          <dc:date>2012-02-06T20:20:33Z</dc:date>
          <dc:date>2012-02-06T20:20:33Z</dc:date>
          <dc:date>2011-12</dc:date>
          <dc:date>2012-02-06T20:20:33Z</dc:date>
          <dc:date>2011-12</dc:date>
          <dc:description>During an Internet distributed denial-of-service (DDoS) attack, attackers pose as
a superpower overloading bandwidth and services that otherwise would have been
lightly used by genuine users. These legitimate users send few packets and occasionally
back-off and fail while competing for resources. The Internet architecture
provides only modest support for verifying the true origin of a packet or intention
of a sender. This makes identification and filtering of attack traffic difficult.
DDoS attacks could be limited greatly if there were a way to fairly distribute the
resources among the parties despite limited origin integrity.
In our work, we propose two methods for achieving fairness despite no or
partial implementation for integrity verification. Adaptive Selective Verification
(ASV) provides legitimate clients service despite large but bounded attack rates
without any integrity infrastructure. ASV can be implemented, without the cooperation
of the core routers, by slight modification of the client and server applications.
The other system is Integrity Based Queuing (IBQ). In this work, we expect
that integrity will not be perfect, but observe that even an imperfect implementation
can improve the effectiveness of queuing when parities with better a integrity
level are incentivized. ASV and IBQ together create a mechanism for incentives,
infrastructure and independence for network service assurance.
ASV is shown to be efficient in terms of bandwidth consumption using network
simulations. It differs from previously-investigated adaptive mechanisms
for bandwidth based payment by requiring very limited state on server. Our study
of IBQ includes proof of direct relationship of integrity to service, a network
simulation for comparative study, simulation with real attack traffic and security
analysis.
Our network assurance architecture provides a synergistic approach for defending
against DDoS attacks. With moderate infrastructure support, IBQ can be an
architecture to provide graded source validation on the Internet. Clients that do not
have the support from the ISP, use their spare bandwidth with ASV for service.</dc:description>
          <dc:description>Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2011-11-26T19:22:54Z
Item was in collections:
University of Illinois Theses &amp; Dissertations (ID: 1)
No. of bitstreams: 2
Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5)
Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5)</dc:description>
          <dc:description>Made available in DSpace on 2012-02-06T20:20:33Z (GMT). No. of bitstreams: 3
Khan_Fariba.pdf: 7007314 bytes, checksum: bf13f67af3c77267ebd744a198b7f140 (MD5)
Thesis Raw.zip: 16367476 bytes, checksum: ed4899cfec2e0c3d8279181d5b15f385 (MD5)
license.txt: 4059 bytes, checksum: a3f79d0f6cf6a70babad8b2d2b568c41 (MD5)</dc:description>
          <dc:identifier>http://hdl.handle.net/2142/29832</dc:identifier>
          <dc:language>en</dc:language>
          <dc:rights>Copyright 2011 Fariba Khan</dc:rights>
          <dc:subject>Distributed Denial of Service (DDoS)</dc:subject>
          <dc:subject>Incentives</dc:subject>
          <dc:subject>Integrity</dc:subject>
          <dc:subject>Fairness</dc:subject>
          <dc:subject>Spoofing Index</dc:subject>
          <dc:title>Assuring network service with bandwidth and integrity based fairness</dc:title>
          <dc:type>Dissertation / Thesis</dc:type>
          <dc:type>text</dc:type>
          <degree>
            <department>Computer Science</department>
            <departmentCode>1434</departmentCode>
            <discipline>Computer Science</discipline>
            <disciplineCode>0112</disciplineCode>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <level>Dissertation</level>
            <name>Ph.D.</name>
            <program>PHD:Computer Science -UIUC</program>
            <programCode>10KS0112PHD</programCode>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
