SLA-based complementary approach for network intrusion detection

被引:12
作者
Ahmed, Abdulghani Ali [1 ]
Jantan, Aman [1 ]
Wan, Tat-Chee [1 ]
机构
[1] Univ Sains Malaysia, Sch Comp Sci, Usm 1180, Penang, Malaysia
关键词
SLA; Intrusions detection; Differentiated service; MPLS technique; Complementary measurements; ANOMALY DETECTION; QOS;
D O I
10.1016/j.comcom.2011.03.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enhancing the intrusion detection system is essential to maintain user confidence in network services security. However, the threat of intruders on Internet services is prevalent. This paper proposes a distributed edge-to-edge complementary approach for intrusion detection in a DiffServ/MPLS domain. The QoS metrics are inspected at the edges routers to determine anomalous behavior in the network traffic. Consumed ratios of one-way delay variation (OWDV) and packet loss are computed to monitor service level agreement (SLA) violations. The bandwidth ratio is measured to differentiate abnormal from normal traffic as well as to detect multiple intrusions launched simultaneously. We employed SLA as a comparison scale to infer the deviation between the users consumed ratios and the predefined ratios in the SLA. Service violation occurs and intrusion may be launched when the predefined ratios are exceeded. The complementary services of DiffServ and MPLS techniques guarantee accurate measurements, whereas the complementary measurements of active and passive techniques immunize network performance against scalability limitation. Simulation results indicate that the proposed approach is capable of monitoring SLA violations and can filter out traffic of intruders who breach SLA without disturbing the normal traffic of legitimate users. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:1738 / 1749
页数:12
相关论文
共 52 条
[1]  
AHMED AA, 2010, JDCTA, V4, P122
[2]  
AHMED AG, 2009, P 3 INT C WORKSH ADV, P598
[3]  
AHSAN SFB, 2005, QOS NETWORK DOMAINS, V15, P11
[4]  
[Anonymous], 2000, 9915 CHALM U DEP COM
[5]  
[Anonymous], NETWORK SIMULATOR NS
[6]   MPLS and traffic engineering in IP networks [J].
Awduche, DO .
IEEE COMMUNICATIONS MAGAZINE, 1999, 37 (12) :42-47
[7]  
BARDEN ER, 1997, RFC2205
[8]  
CHRISTIAN K, 2004, ACM, V34, P51
[9]  
*CISC SYST INC, 2009, QUAL SERV NETW INT T
[10]  
CORRAL GTJ, 2003, P PAM WORKSH 03, P3