Title :
Quantitative threat assessment of denial of service attacks on service availability
Author :
Chen, Xiuzhen ; Li, Shenghong ; Ma, Jin ; Li, Jianhua
Author_Institution :
Sch. of Inf. Security Eng., Shanghai Jiaotong Univ., Shanghai, China
Abstract :
With increasing denial of service attacks on network infrastructure, there is an urgent need to develop technique to assess the threat of attacks on network security online. A novel model of security threat assessment relying on several predefined metrics of network performance is proposed to measure the impact of denial of service attacks on service availability in real time. This model applies the technique of D-S evidence reasoning to fuse three metrics of network performance, which are designed carefully to reflect the reliability of service availability in three perspectives. Our approach includes three steps: determining performance parameters, calculating threat index and characterizing the threat state of service availability. Compared with other methods, this method avoids the unilateral result obtained from single sensor, helps administrators to determine security threat state, and provides threat evolution of service availability over time. Testing in a real network environment shows that this method greatly improves the accuracy of threat assessment, demonstrates the impact of denial of service attacks on network security is different from the beginning to the end of DoS attacks, and provides administrators with threat evolution picture macroscopically. Moreover, it lays the foundation for administrators to adopt security response policies in real time for reliable and robust network.
Keywords :
computer network performance evaluation; computer network reliability; inference mechanisms; security of data; telecommunication security; D-S evidence reasoning; denial of service attack; network infrastructure; network performance; network security; quantitative threat assessment; robust network; security response policy; security threat assessment; service availability; threat evolution; Availability; Computer crime; Indexes; Linux; Measurement; Servers; Network security; denial of service attack; evidence reasoning; quantitative assessment; threat assessment;
Conference_Titel :
Computer Science and Automation Engineering (CSAE), 2011 IEEE International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-1-4244-8727-1
DOI :
10.1109/CSAE.2011.5953208