An Inter-Domain Attack Mitigating Solution

被引:0
|
作者
Akin, Gokhan [1 ]
Buk, Ozan [2 ]
Ucar, Erdem [1 ]
机构
[1] Trakya Univ, Inst Sci, Dept Comp Engn, Edirne, Turkey
[2] Istanbul Tech Univ, Informat Inst, Satellite Commun & Remote Sensing Program, Istanbul, Turkey
关键词
Denial of service; Cyber; Attack; Software defined network; Openflow; Flowspec; DDOS ATTACKS; DEFENSE-MECHANISMS; ANOMALY DETECTION; SDN;
D O I
10.3906/elk-1904-179
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Online services on the Internet are increasing day by day, and in parallel, the number of cyber-attacks is rapidly increasing. These attacks are not always about data theft, but they can cause severe damage by denial of service attacks. Intrusion Prevention System products that many organizations use at the border of their enterprise networks are not strong enough to protect against DoS attacks. The typical way to mitigate such attacks is to get support from a service provider. However, a service provider only provides solutions for the traffic originating from itself. If the source of attack is in another ISP domain, it is possible to inform that ISP via phone or e-mail. As a result, the source of the attack is blocked by the manual intervention of the service provider whose domain hosts it. Border Gateway Protocol (BGP) based solutions are also available for automating a blocking system, but not all enterprise networks support BGP. In this research, we have developed a centralized automation solution for software defined network (SDN) environments that is capable of preventing cyber-attacks at the source of attack. This solution does not require any BGP support. Non-SDN environments can also use this attack mitigation and notification system. In the long run, we may use this system to create a national protection shield in order to mitigate Cybersecurity attacks.
引用
收藏
页码:757 / 772
页数:16
相关论文
共 50 条
  • [1] A SOLUTION TO INTER-DOMAIN POLICY DISPUTES
    Guo, Huaming
    Yao, Nan
    Ma, Yunfei
    Zhang, Hongke
    CIICT 2008: PROCEEDINGS OF CHINA-IRELAND INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATIONS TECHNOLOGIES 2008, 2008, : 341 - 345
  • [2] Characterizing and mitigating inter-domain policy violations in overlay routes
    Seetharaman, Srinivasan
    Ammar, Mostafa
    PROCEEDINGS OF THE 2006 IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS, 2006, : 253 - +
  • [3] An hierarchical inter-domain authenticated source address validation solution
    Li, Jie
    Wu, Jian-Ping
    Xu, Ke
    Chen, Wen-Long
    Jisuanji Xuebao/Chinese Journal of Computers, 2012, 35 (01): : 85 - 100
  • [4] Web-service solution for inter-domain QoS negotiation
    Obreja, Serban Georgica
    Borcoci, Eugen
    Lupu, Radu
    Iorga, Radu
    CTRQ 2008: INTERNATIONAL CONFERENCE ON COMMUNICATION THEORY, RELIABILITY, AND QUALITY OF SERVICE, PROCEEDINGS, 2008, : 95 - 102
  • [5] A Run-Time Solution to Inter-Domain Policy Disputes
    Guo, Huaming
    Luo, Hongbin
    Zhang, Hongke
    GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2008,
  • [6] A BPM-Based Solution for Inter-domain Circuit Management
    Cardoso de Santanna, Jose Jair
    Wickboldt, Juliano Araujo
    Granville, Lisandro Zambenedetti
    2012 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2012, : 385 - 392
  • [7] Distributed inter-domain link capacity optimization for inter-domain IP/MPLS routing
    Tomaszewski, Artur
    Pioro, Michat
    Mycek, Mariusz
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 1872 - +
  • [8] Inter-domain Coordination Models
    Agiatzidou, Eleni
    Courcoubetis, Costas
    Dugeon, Olivier
    Johansen, Finn-Tore
    Stamoulis, George D.
    NETWORKING 2012 WORKSHOPS, 2012, 7291 : 113 - 120
  • [9] An architecture for inter-domain troubleshooting
    Thaler D.G.
    Ravishankar C.V.
    Journal of Network and Systems Management, 2004, 12 (2) : 155 - 189
  • [10] An architecture for inter-domain troubleshooting
    Thaler, DG
    Ravishankar, CV
    SIXTH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 1997, : 516 - 523