Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON...
Published in: | Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024 |
---|---|
Main Author: | |
Format: | Conference paper |
Language: | English |
Published: |
Institute of Electrical and Electronics Engineers Inc.
2024
|
Online Access: | https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73 |
id |
2-s2.0-85208425743 |
---|---|
spelling |
2-s2.0-85208425743 Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A. Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON 2024 Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024 10.1109/ATNT61688.2024.10719283 https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73 Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON to address this vulnerability. SE-DBA includes a detection phase for abnormal behavior and a mitigation phase that reduces bandwidth allocation to identified attackers. Network simulations using OMNET++ demonstrate that SE-DBA improves SE-DBA increases the lawful ONU's network resilience during attacks by 50% compared to GIANT. The results also demonstrate SE-DBA's ability to penalize the malicious ONU by reducing its bandwidth request to 20% of its original request. © 2024 IEEE. Institute of Electrical and Electronics Engineers Inc. English Conference paper |
author |
Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A. |
spellingShingle |
Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A. Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
author_facet |
Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A. |
author_sort |
Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A. |
title |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
title_short |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
title_full |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
title_fullStr |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
title_full_unstemmed |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
title_sort |
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON |
publishDate |
2024 |
container_title |
Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024 |
container_volume |
|
container_issue |
|
doi_str_mv |
10.1109/ATNT61688.2024.10719283 |
url |
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73 |
description |
Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON to address this vulnerability. SE-DBA includes a detection phase for abnormal behavior and a mitigation phase that reduces bandwidth allocation to identified attackers. Network simulations using OMNET++ demonstrate that SE-DBA improves SE-DBA increases the lawful ONU's network resilience during attacks by 50% compared to GIANT. The results also demonstrate SE-DBA's ability to penalize the malicious ONU by reducing its bandwidth request to 20% of its original request. © 2024 IEEE. |
publisher |
Institute of Electrical and Electronics Engineers Inc. |
issn |
|
language |
English |
format |
Conference paper |
accesstype |
|
record_format |
scopus |
collection |
Scopus |
_version_ |
1818940555184308224 |