A summary of detection of denial-of-QoS attacks on DiffServ networks

被引:0
|
作者
Wu, X [1 ]
Mahadik, VA [1 ]
Reeves, DS [1 ]
机构
[1] MCNC RDI, Res Triangle Pk, NC 27709 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This paper summarizes our approach of detecting denial of QoS attacks on DiffServ networks. Our approach focuses on online quick detection, scalability to large networks, and a low false alarm generation rate. Sensors sample QoS metric at strategic points and we detect anomalies in sampled network flow statistics using the X-2 and EWMA Control Chart test methods. We also use rule-based intrusion detection of SLAs as a complement to these techniques. We have tested our intrusion detection approach using emulation on a testbed, and using simulation. Attacks are detected 100% of the time, and require from under a minute to approximately 15 minutes to detect. The false alarm rate at the sensitivity level used to achieve these detection results is less than 1%. These results make our work a strong candidate for deployment.
引用
收藏
页码:277 / 282
页数:6
相关论文
共 50 条
  • [41] Resource allocation and admission control styles in QoS DiffServ networks
    Gerla, M
    Casetti, C
    Lee, SS
    Reali, G
    QUALITY OF SERVICE IN MULTISERVICE IP NETWORKS, PROCEEDINGS, 2001, 1989 : 113 - 128
  • [42] Diffserv-based QoS over ATM access networks
    Ishihara, T
    Tanaka, J
    Goto, M
    Oda, S
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2001, E84B (06) : 1498 - 1503
  • [43] AQM for dynamic QoS adaptation in DiffServ networks based on STAC
    Farrokhian, Mehdi
    Haeri, Mohammad
    2006 SICE-ICASE INTERNATIONAL JOINT CONFERENCE, VOLS 1-13, 2006, : 1380 - +
  • [44] On Denial of Service Attacks in Software Defined Networks
    Zhang, Peng
    Wang, Huanzhao
    Hu, Chengchen
    Lin, Chuang
    IEEE NETWORK, 2016, 30 (06): : 28 - 33
  • [45] Defending networks against denial of service attacks
    Gelenbe, E
    Gellman, M
    Loukas, G
    UNMANNED/UNATTENDED SENSORS AND SENSOR NETWORKS, 2004, 5611 : 233 - 243
  • [46] Denial of Service Attacks in Networks with Tiny Buffers
    Havary-Nassab, Veria
    Koulakezian, Agop
    Ganjali, Yashar
    IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, 2009, : 91 - +
  • [47] Distributed denial of service attacks and detection mechanisms
    Rafsanjani, Marjan Kuchaki
    Kazeminejad, Neda
    JOURNAL OF COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING, 2014, 14 (06) : 329 - 345
  • [48] Charging QoS Inter-Domain Networks: IntServ over DiffServ
    El-Haddadeh, R.
    Watts, S. J.
    Taylor, G. A.
    GLOBECOM 2006 - 2006 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2006,
  • [49] Multipath QoS routing of supporting DiffServ in mobile ad hoc networks
    Li, XF
    Cuthbert, L
    SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERNG, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING AND FIRST AICS INTERNATIONAL WORKSHOP ON SELF-ASSEMBLING WIRELESS NETWORKS, PROCEEDINGS, 2005, : 308 - 313
  • [50] QoS provisioning and pricing for delay-sensitive applications in DiffServ networks
    Zhang, J
    Hämäläinen, T
    Raatikainen, P
    Kaario, K
    PERFORMANCE CHALLENGES FOR EFFICIENT NEXT GENERATION NETWORKS, VOLS 6A-6C, 2005, 6A-6C : 1601 - 1610