Quantitative threat assessment of denial of service attacks on service availability

Xiuzhen Chen, Shenghong Li, Jin Ma, Jianhua Li
{"title":"Quantitative threat assessment of denial of service attacks on service availability","authors":"Xiuzhen Chen, Shenghong Li, Jin Ma, Jianhua Li","doi":"10.1109/CSAE.2011.5953208","DOIUrl":null,"url":null,"abstract":"With increasing denial of service attacks on network infrastructure, there is an urgent need to develop technique to assess the threat of attacks on network security online. A novel model of security threat assessment relying on several predefined metrics of network performance is proposed to measure the impact of denial of service attacks on service availability in real time. This model applies the technique of D-S evidence reasoning to fuse three metrics of network performance, which are designed carefully to reflect the reliability of service availability in three perspectives. Our approach includes three steps: determining performance parameters, calculating threat index and characterizing the threat state of service availability. Compared with other methods, this method avoids the unilateral result obtained from single sensor, helps administrators to determine security threat state, and provides threat evolution of service availability over time. Testing in a real network environment shows that this method greatly improves the accuracy of threat assessment, demonstrates the impact of denial of service attacks on network security is different from the beginning to the end of DoS attacks, and provides administrators with threat evolution picture macroscopically. Moreover, it lays the foundation for administrators to adopt security response policies in real time for reliable and robust network.","PeriodicalId":138215,"journal":{"name":"2011 IEEE International Conference on Computer Science and Automation Engineering","volume":"29 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-06-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"19","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 IEEE International Conference on Computer Science and Automation Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSAE.2011.5953208","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 19

Abstract

With increasing denial of service attacks on network infrastructure, there is an urgent need to develop technique to assess the threat of attacks on network security online. A novel model of security threat assessment relying on several predefined metrics of network performance is proposed to measure the impact of denial of service attacks on service availability in real time. This model applies the technique of D-S evidence reasoning to fuse three metrics of network performance, which are designed carefully to reflect the reliability of service availability in three perspectives. Our approach includes three steps: determining performance parameters, calculating threat index and characterizing the threat state of service availability. Compared with other methods, this method avoids the unilateral result obtained from single sensor, helps administrators to determine security threat state, and provides threat evolution of service availability over time. Testing in a real network environment shows that this method greatly improves the accuracy of threat assessment, demonstrates the impact of denial of service attacks on network security is different from the beginning to the end of DoS attacks, and provides administrators with threat evolution picture macroscopically. Moreover, it lays the foundation for administrators to adopt security response policies in real time for reliable and robust network.
拒绝服务攻击对服务可用性的定量威胁评估
随着对网络基础设施的拒绝服务攻击的增加,迫切需要开发在线评估攻击对网络安全威胁的技术。提出了一种新的安全威胁评估模型,该模型依赖于几个预定义的网络性能指标来实时测量拒绝服务攻击对服务可用性的影响。该模型采用D-S证据推理技术,融合了三个网络性能指标,这些指标经过精心设计,从三个角度反映了服务可用性的可靠性。我们的方法包括三个步骤:确定性能参数、计算威胁指数和表征服务可用性的威胁状态。与其他方法相比,该方法避免了从单个传感器获得的单边结果,帮助管理员判断安全威胁状态,并提供了服务可用性随时间的威胁演化。在真实网络环境中进行的测试表明,该方法大大提高了威胁评估的准确性,展示了拒绝服务攻击对网络安全的影响从DoS攻击的开始到结束都是不同的,为管理员提供了一个宏观的威胁演化图。为管理员实时采取安全响应策略,保证网络的可靠性和鲁棒性奠定了基础。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信