Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON

Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON...

Full description

Bibliographic Details
Published in:Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024
Main Author: Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
Format: Conference paper
Language:English
Published: Institute of Electrical and Electronics Engineers Inc. 2024
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73
id 2-s2.0-85208425743
spelling 2-s2.0-85208425743
Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
2024
Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024


10.1109/ATNT61688.2024.10719283
https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73
Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON to address this vulnerability. SE-DBA includes a detection phase for abnormal behavior and a mitigation phase that reduces bandwidth allocation to identified attackers. Network simulations using OMNET++ demonstrate that SE-DBA improves SE-DBA increases the lawful ONU's network resilience during attacks by 50% compared to GIANT. The results also demonstrate SE-DBA's ability to penalize the malicious ONU by reducing its bandwidth request to 20% of its original request. © 2024 IEEE.
Institute of Electrical and Electronics Engineers Inc.

English
Conference paper

author Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
spellingShingle Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
author_facet Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
author_sort Atan F.M.; Zulkifli N.; Idrus S.M.; Zin N.A.M.; Ismail N.A.
title Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
title_short Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
title_full Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
title_fullStr Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
title_full_unstemmed Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
title_sort Mitigating DBA Exploits: Enhanced Security Against Degradation Attacks in XG-PON
publishDate 2024
container_title Conference Proceedings - IEEE International Conference on Advanced Telecommunication and Networking Technologies: Empowering Telecommunication Technologies for Sustainable Future, ATNT 2024
container_volume
container_issue
doi_str_mv 10.1109/ATNT61688.2024.10719283
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-85208425743&doi=10.1109%2fATNT61688.2024.10719283&partnerID=40&md5=3d238b15ccd5933e3161ecb4c9bbac73
description Next-Generation Gigabit Passive Optical Networks (NG-PON) improve bandwidth and data rates, but their upstream channel security has been overlooked due to assumptions about its point-to-point nature. This paper introduces a Security-Enhanced Dynamic Bandwidth Allocation (SE-DBA) algorithm for XG-PON to address this vulnerability. SE-DBA includes a detection phase for abnormal behavior and a mitigation phase that reduces bandwidth allocation to identified attackers. Network simulations using OMNET++ demonstrate that SE-DBA improves SE-DBA increases the lawful ONU's network resilience during attacks by 50% compared to GIANT. The results also demonstrate SE-DBA's ability to penalize the malicious ONU by reducing its bandwidth request to 20% of its original request. © 2024 IEEE.
publisher Institute of Electrical and Electronics Engineers Inc.
issn
language English
format Conference paper
accesstype
record_format scopus
collection Scopus
_version_ 1818940555184308224