Securing MPTCP Connections: A Solution for Distributed NIDS Environments

dc.contributor.author Meira,JP en
dc.contributor.author Rui Pedro Monteiro en
dc.contributor.author João Marco en
dc.contributor.other 6946 en
dc.contributor.other 8658 en
dc.date.accessioned 2023-01-18T21:31:10Z
dc.date.available 2023-01-18T21:31:10Z
dc.date.issued 2022 en
dc.description.abstract With continuous technological advancement, multihomed devices are becoming common. They can connect simultaneously to multiple networks through different interfaces. However, since TCP sessions are bound to one interface per device, it hampers applications from taking advantage of all the available connected networks. This has been solved by MPTCP, introduced as a seamless extension to TCP, allowing more reliable sessions and enhanced throughput. However, MPTCP comes with an inherent risk, as it becomes easier to fragment attacks towards evading NIDS. This paper presents a study of how MPTCP can be used to evade NIDS through simple cross-path attacks. It also introduces tools to facilitate assessing MPTCP-based services in diverse network topologies using an emulation environment. Finally, a new solution is proposed to prevent cross-path attacks through uncoordinated networks. This solution consists of a hostlevel plugin that allows MPTCP sessions only through trusted networks, even in the presence of a NAT. en
dc.identifier P-00X-JH1 en
dc.identifier.uri http://dx.doi.org/10.1109/lcn53696.2022.9843271 en
dc.identifier.uri https://repositorio.inesctec.pt/handle/123456789/13476
dc.language eng en
dc.rights info:eu-repo/semantics/openAccess en
dc.title Securing MPTCP Connections: A Solution for Distributed NIDS Environments en
dc.type en
dc.type Publication en
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
P-00X-JH1.pdf
Size:
358.23 KB
Format:
Adobe Portable Document Format
Description: