DocumentCode
627476
Title
Guaranteeing confidentiality in multi-domain networks: The PCE Anomaly Detector (PAD)
Author
Gharbaoui, M. ; Paolucci, Francesco ; Giorgetti, A. ; Castoldi, Piero ; Martini, Ben
Author_Institution
TeCIP Inst., Scuola Superiore Sant´Anna, Pisa, Italy
fYear
2013
fDate
27-31 May 2013
Firstpage
485
Lastpage
491
Abstract
Traffic Engineering (TE) is currently required in multi-domain multi-provider networks to effectively exploit network resources. The Path Computation Element (PCE) architecture has been recently proposed for actually enabling TE in the aforementioned scenario. However, it might be exposed to several confidentiality leaks among network providers. Numerous research works in the context of multi-domain networks recently focused on authentication, authorization, and encryption mechanisms to mitigate the PCE architecture confidentiality leaks. With respect to such works, this paper tackles confidentiality issues from a different perspective, i.e., the detection of malicious utilization of path computation services aiming at inferring salient intra-domain information of other providers. This paper proposes the PCE Anomaly Detector (PAD) for detecting malicious PCE using a statistical anomaly-based approach. The novel statistical model used by the PAD is accurately described and PAD building blocks are presented. Simulation results show the effectiveness of the proposed approach that achieves an effective trade-off between the false alarms probability and the detection delay.
Keywords
Internet; cryptography; message authentication; telecommunication traffic; Internet; PAD building blocks; PCE anomaly detector; authentication; authorization; confidentiality leaks; detection delay; encryption mechanism; false alarms probability; intradomain information; multidomain networks; network providers; path computation element; traffic engineering; Bandwidth; Computer architecture; Detectors; Monitoring; Probability; Testing; Topology; Confidentiality; Internet; Multi-domain; Multi-provider; PCE; Security; Sequential Hypothesis Testing; Traffic Engineering;
fLanguage
English
Publisher
ieee
Conference_Titel
Integrated Network Management (IM 2013), 2013 IFIP/IEEE International Symposium on
Conference_Location
Ghent
Print_ISBN
978-1-4673-5229-1
Type
conf
Filename
6573022
Link To Document