Assessing denial of service vulnerabilities in DOCSIS

  • Authors:
  • Scott Moser;Jim Martin

  • Affiliations:
  • Clemson University, Clemson, S.C.;Clemson University, Clemson, S.C.

  • Venue:
  • Proceedings of the 44th annual Southeast regional conference
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In previous work a DOCSIS model was added to 'ns' to allow simulations to be run to analyze the performance of DOCSIS. These simulations showed that congestion caused by the asymmetric data paths and the MAC contention process caused several performance problems. It was shown that ACK compression could cause a drop in downstream throughput of TCP streams. A denial of service (DoS) threat was also identified, due to the DOCSIS contention process, allowing an attacker to overload the upstream channel, deteriorating the service quality perceived by all active subscribers.Using an actual DOCSIS system, this study continues that simulation effort by running tests on a live system. The purpose is to show that the problems identified by simulation do exist in practice and to collect information from a live system that can be used to validate and improve the simulation model.