Virtual Network Functions Placement for Defense Against Distributed Denial of Service Attacks

被引:1
|
作者
Haddad-Vanier, Sonia [1 ]
Gicquel, Celine [2 ]
Boukhatem, Lila [2 ]
Lazri, Kahina [3 ]
Chaignon, Paul [3 ]
机构
[1] SAMM Univ Paris I Pantheon Sorbonne, Paris, France
[2] Univ Paris Sud, Univ Paris Saclay, LRI, CNRS, Orsay, France
[3] Orange Labs Prod & Serv, Meylan, France
关键词
Network Optimization; Distributed Denial of Service (DDos) Attacks; Network Function Virtualizing (NFV); Mathematical Programming; Mixed Integer Linear Program (MILP); Bilevel Programming;
D O I
10.5220/0007397601420150
中图分类号
C93 [管理学]; O22 [运筹学];
学科分类号
070105 ; 12 ; 1201 ; 1202 ; 120202 ;
摘要
In this paper, we are interested in the problem of Virtual Network Function (NFV) placement to counter Distributed Denial of Service (DDoS) attacks. A DDoS attack is one of the most common and damaging types of cyberattacks. In Network Function Virtualization (NFV) technology network functions, more specifically security mechanisms, are implemented as software. Such approach significantly reduces the cost of the infrastructure and simplifies the deployment of new services. We propose two new models for this critical and complex problem. The first model is a mixed-integer linear program aiming at eliminating all DDos attacks before they reach their target. As its size grows exponentially with the network size, we propose a constraint generation algorithm to solve it. The numerical results obtained for different realistic network instances show the effectiveness of our approach. The second model is a bilevel programming problem that achieves a trade-off between NFVs placement costs and security levels requirements. Our results show that this mechanisms overcomes DDos attacks by effectively filtering attacks while minimizing the total cost of deployed NFV.
引用
收藏
页码:142 / 150
页数:9
相关论文
共 50 条
  • [1] Distributed defense against distributed denial-of-service attacks
    Shi, W
    Xiang, Y
    Zhou, WL
    [J]. DISTRIBUTED AND PARALLEL COMPUTING, 2005, 3719 : 357 - 362
  • [2] Characterization of defense mechanisms against distributed denial of service attacks
    Chen, LC
    Longstaff, TA
    Carley, KM
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 665 - 678
  • [3] A Cooperative Mechanism to Defense Against Distributed Denial of Service Attacks
    Beitollahi, Hakem
    Deconinck, Geert
    [J]. TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 11 - 20
  • [4] Defense mechanisms against Distributed Denial of Service attacks : A survey
    Manavi, Mousa Taghizadeh
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2018, 72 : 26 - 38
  • [5] VFence: A Defense against Distributed Denial of Service Attacks using Network Function Virtualization
    Jakaria, A. H. M.
    Yang, Wei
    Rashidi, Bahman
    Fung, Carol
    Rahman, M. Ashigur
    [J]. PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 431 - 436
  • [6] A game inspired defense mechanism against distributed denial of service attacks
    Bedi, Harkeerat
    Shiva, Sajjan
    Roy, Sankardas
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (12) : 2389 - 2404
  • [7] A Hybrid Defense Technique for ISP Against the Distributed Denial of Service Attacks
    Moon, Young Hoon
    Choi, Suk Bong
    Kim, Huy Kang
    Yoo, Changsok
    [J]. APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (05): : 2347 - 2359
  • [8] Optimal deployment of virtual network functions for securingtelecommunication networks against distributed denial of service attacks: Arobust optimization approach
    Gicquel, Celine
    Vanier, Sonia
    Papadimitriou, Alexandros
    [J]. COMPUTERS & OPERATIONS RESEARCH, 2022, 146
  • [9] Defense Analysis Against Store and Forward Distributed Reflective Denial of Service Attacks
    Fraiwan, M.
    Al-Quran, Fidaa
    Al-Duwairi, Basheer
    [J]. PROCEEDINGS OF THE 2018 13TH INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION TECHNOLOGY (IIT), 2018, : 111 - 116
  • [10] A Survey of Defense Mechanisms Against Application Layer Distributed Denial of Service Attacks
    Wang, Yadong
    Liu, Lianzhong
    Sun, Bo
    Li, Yingbo
    [J]. PROCEEDINGS OF 2015 6TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE, 2015, : 1034 - 1037