• DocumentCode
    1181582
  • Title

    Quality-of-protection (QoP)-an online monitoring and self-protection mechanism

  • Author

    Hariri, Salim ; Qu, Guangzhi ; Modukuri, Ramkishore ; Chen, Huoping ; Yousif, Mazin

  • Author_Institution
    Internet Technol. Lab., Univ. of Arizona, Tucson, AZ, USA
  • Volume
    23
  • Issue
    10
  • fYear
    2005
  • Firstpage
    1983
  • Lastpage
    1993
  • Abstract
    With increasing faults and attacks on the Internet infrastructure, there is an impending need to provide automatic techniques to detect and mitigate the impact of attacks on network services. Denial-of-service attacks have been successful in denying legitimate traffic access to its required resources because existing routing protocols treat the attacking traffic equally as any normal traffic. This paper presents a proactive network defense framework that can be integrated with existing quality-of-service (QoS) protocols to provide differentiated services to network traffic flows based on their distance from the normal behavior. We introduce a new metric that we refer to as abnormality distance (AD) metric that can be used to classify traffic into normal, probable normal, probable abnormal (suspicious traffic), and abnormal (attacking traffic). The AD metric can then be used in conjunction with any QoS protocol to give high priority to normal traffic and lower priority to abnormal traffic. We demonstrate through several examples, how our approach can dynamically detect attacks, quantify their impact, and how to reduce the impacts and recover from them.
  • Keywords
    DiffServ networks; Internet; authorisation; fault diagnosis; monitoring; quality of service; routing protocols; telecommunication security; telecommunication traffic; AD metric; Internet infrastructure; QoP; QoS protocol; abnormality distance; automatic technique; denial-of-service attack; differentiated service; network fault; network traffic flow; online monitoring; proactive defense network; quality-of-protection; quality-of-service; routing protocol; self-protection mechanism; Computer crime; Diffserv networks; IP networks; Monitoring; Network servers; Protection; Protocols; Quality of service; Telecommunication traffic; Web and internet services; Abnormality distance (AD); network attack; proactive defense; quality-of-protection (QoP);
  • fLanguage
    English
  • Journal_Title
    Selected Areas in Communications, IEEE Journal on
  • Publisher
    ieee
  • ISSN
    0733-8716
  • Type

    jour

  • DOI
    10.1109/JSAC.2005.854122
  • Filename
    1514527