Named Data Networking (NDN) is a prominent realization of the vision of Information-Centric Networking. The NDN architecture adopts name-based routing and location-independent data retrieval. Among other important features, NDN integrates security mechanisms and focuses on protecting the content rather than the communications channels. Along with a new architecture come new threats and NDN is no exception. NDN is a potential target for new network attacks such as Interest Flooding Attacks (IFAs). Attackers take advantage of IFA to launch (D)DoS attacks in NDN. Many IFA detection and mitigation solutions have been proposed in the literature. However, there is no comprehensive review study of these solutions that has been proposed so far. Therefore, in this paper, we propose a survey of the various IFAs with a detailed comparative study of all the relevant proposed solutions as counter-measures against IFAs. We also review the requirements for a complete and efficient IFA solution and pinpoint the various issues encountered by IFA detection and mitigation mechanisms through a series of attack scenarios. Finally, in this survey, we offer an analysis of the open issues and future research directions regarding IFAs. This manuscript consists of an extended version of the paper published in ACM Computing Surveys: https://dl.acm.org/doi/10.1145/3539730.
翻译:命名数据网络(NDN)是信息中心网络愿景的显著实现。NDN架构采用以名称为基础的路由和位置独立的数据检索,但除其他重要特征外,NDN整合了安全机制,侧重于保护内容而不是通信渠道。随着新的架构出现新的威胁,NDN也不例外。NDN是新的网络袭击的潜在目标,如 " 利益泛滥袭击 " (IFAs)等。攻击者利用IFA在NDN发起(D)DoS袭击。文献中提出了许多国际家庭基金探测和减缓解决方案。然而,迄今为止,没有对这些解决方案进行全面审查研究。因此,我们在本文件中提议对各种国际家庭基金进行一项调查,对作为对付IFAs袭击的对策的所有相关拟议解决方案进行详细比较研究。我们还审查了完整和高效国际家庭基金解决方案的要求,并通过一系列攻击情景来确定国际家庭基金探测和减缓机制遇到的各种问题。最后,我们在本次调查中提供了对迄今为止提出的这些解决方案的综合审查研究研究研究研究研究研究。我们提出了关于IFA/ARCM3的公开问题和未来研究方向。