DocumentCode :
3694401
Title :
Mitigating DoS attacks in identity management systems through reorganizations
Author :
Ricardo Macedo;Yacine Ghamri-Doudane;Michele Nogueira
Author_Institution :
NR2 - Federal University of Paraná
fYear :
2015
Firstpage :
27
Lastpage :
34
Abstract :
Ensuring identity management (IdM) systems availability plays a key role to support networked systems. Denial-of-Service (DoS) attacks can make IdM operations unavailable, preventing the use of computational resources by legitimate users. In the literature, the main countermeasures against DoS over IdM systems are based on either the application of external resources to extend the system lifetime (replication) or on DoS attacks detection. The first approach increases the solutions cost, and in general the second approach is still prone to high rates of false negatives and/or false positives. Hence, this work presents SAMOS, a novel and paradigm-shifting Scheme for DoS Attacks Mitigation by the reOrganization and optimization of the IdM System. SAMOS optimizes the reorganization of the IdM system components founded on optimization techniques, minimizing DoS effects and improving the system lifetime. SAMOS is based on the unavailabilities effects such as the exhaustion of processing and memory resources, eliminating the dependence of attacks detection. Furthermore, SAMOS employs operational IdPs from the IdM system to support the demand of the IdM system, differently from replication approaches. Results considering data from two real IdM systems indicate the scheme viability and improvements. As future works, SAMOS will be prototyped in order to allow performance evaluations in a real testbed.
Keywords :
"Computer crime","Optimization","Authentication","IP networks","Cloud computing","Proposals"
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (LANOMS), 2015 Latin American
Type :
conf
DOI :
10.1109/LANOMS.2015.7332666
Filename :
7332666
Link To Document :
بازگشت