Effective Statistical Detection of Smart Confidentiality Attacks in Multi-Domain Networks

被引:5
|
作者
Gharbaoui, Molka [1 ]
Paolucci, Francesco [1 ]
Giorgetti, Alessio [1 ]
Martini, Barbara [2 ]
Castoldi, Piero [1 ]
机构
[1] Scuola Super Sant Anna, TeCIP Inst, Pisa, Italy
[2] Consorzio Nazl Interuniv Telecomunicaz CNIT, Pisa, Italy
关键词
Multi-domain networks; traffic engineering; PCE; BGP; control plane security; sequential hypothesis testing;
D O I
10.1109/TNSM.2013.111113.130482
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The need to preserve information confidentiality among network providers has prevented the actual deployment of effective Traffic Engineering (TE) solutions for QoS-enabled end-to-end connectivity services in multi-domain multi-provider networks. The use of Path Computation Element (PCE) architecture can foster the effective implementation of TE through a centralized engine devoted to end-to-end path computations. However, despite authentication, authorization and encryption, confidentiality issues may arise due to abuses of information included in path computation replies to bogus requests issued by malicious PCEs. This paper first demonstrates the security leak allowing the exposure of intra-domain information in current inter-PCE path computation procedures. Then it proposes an anomaly-based approach, namely PCE Anomaly Detector (PAD) in order to detect malicious utilization of path computation services. The proposed PAD employs a novel double-step multi-dimensional formulation based on the Sequential Hypothesis Testing (SHT) statistical classification procedure, able to recognize a suspicious sequence of requests while aiming at inferring confidential information about other domains. PAD is extensively evaluated through simulations. Results show good performance in terms of detection capabilities while guaranteeing the trade-off between accuracy and responsiveness, minimizing false alarm occurrences. Robustness against smart attacks is also proved with respect to a comprehensive set of attack patterns and under different network load conditions. Finally, intra-domain information exposition is evaluated, showing the PAD ability to preserve confidentiality.
引用
收藏
页码:383 / 397
页数:15
相关论文
共 50 条
  • [1] Preserving Confidentiality in PCE-based Multi-domain Networks
    Paolucci, Francesco
    Gharbaoui, Molka
    Giorgetti, Alessio
    Cugini, Filippo
    Martini, Barbara
    Valcarenghi, Luca
    Castoldi, Piero
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2011, 3 (05) : 465 - 474
  • [2] Guaranteeing Confidentiality in Multi-domain Networks: the PCE Anomaly Detector (PAD)
    Gharbaoui, M.
    Paolucci, F.
    Giorgetti, A.
    Castoldi, P.
    Martini, B.
    [J]. 2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 485 - 491
  • [3] Multi-domain smart sensors
    Pollehn, HK
    Ahearn, J
    [J]. INFRARED TECHNOLOGY AND APPLICATIONS XXV, 1999, 3698 : 420 - 426
  • [4] Statistical Approach for Detecting Malicious PCE Activity in Multi-domain Networks
    Gharbaoui, Molka
    Paolucci, Francesco
    Giorgetti, Alessio
    Martini, Barbara
    Castoldi, Piero
    [J]. 2012 IEEE 13TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (HPSR), 2012,
  • [5] On Resource Provisioning for Multi-Domain Networks
    Zhang, Xiaolan J.
    Kim, Sun-il
    Lumetta, Steven S.
    [J]. OFC: 2009 CONFERENCE ON OPTICAL FIBER COMMUNICATION, VOLS 1-5, 2009, : 2615 - +
  • [6] QoS routing in multi-domain networks
    Benmohamed, L
    Doshi, B
    [J]. 2005 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS AND SIGNAL PROCESSING (PACRIM), 2005, : 137 - 140
  • [7] MULTI-DOMAIN ATTENTIVE DETECTION NETWORK
    Cho, Sungmin
    Choi, Bowon
    Kim, Do-Hwi
    Kwon, Junseok
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2019, : 2194 - 2198
  • [8] Smart Noise Detection for Statistical Disclosure Attacks
    Rossberger, Marc
    Kesdogan, Dogan
    [J]. SECURE IT SYSTEMS, NORDSEC 2023, 2024, 14324 : 87 - 103
  • [9] Smart Multistage Privacy-Preserving Framework for Intrusion Detection in Multi-Domain SDN
    Padmanabhan, Jayashree
    Prabu, Saranya
    Balakrishnan, Saikrishna
    Vijay, Vinayaka Murthy
    [J]. IETE JOURNAL OF RESEARCH, 2023,
  • [10] Is Semantic Communication Secure? A Tale of Multi-Domain Adversarial Attacks
    Sagduyu, Yalin E.
    Erpek, Tugba
    Ulukus, Sennur
    Yener, Aylin
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (11) : 50 - 55