{"title":"检测DiffServ优先级违规","authors":"Ahmed A. Ghanem, K. Bilal","doi":"10.1109/ICCCEEE.2018.8515848","DOIUrl":null,"url":null,"abstract":"Due to of the fast growth in network technology structure and spread uses in all our life, in the same time the networks threated are rapidly increased. This paper presents an edge to edge model. The aim is to detect intrusion in the networks with little effort on the network resources. by monitoring and detecting the Denial of Service / Distributed Denial of Service (DoS/DDoS) attacks in case of network congestion and their impact on priority level of users. Hybrid threshold used to know if users are violating the network services or not. Random Early Detection (RED) threshold is an adaptive threshold moves between minimum and maximum values, Service Level Agreement (SLA) threshold is a predefined values determined between customer and service provider (SP). RED algorithm used in Quality of Service (QoS) DiffServ environment to monitor the network, when notice the suspicious users exceed the Hybrid threshold, the Detecting Violation in DiffServ Priority (DVDP) model moves to other phase and computes the throughput for suspicious users. This model used Network Simulator 2 (NS2) to simulate the proposed network, this network has users with low level priority triggered a lot of traffic and effected on the high level priority users and consume their bandwidth. This model detect the malicious users affected on the users have high priority, and differentiate with legal users. The accuracy on detected the malicious users estimates about 94%, and a very high sensitivity to the abnormal traffic.","PeriodicalId":6567,"journal":{"name":"2018 International Conference on Computer, Control, Electrical, and Electronics Engineering (ICCCEEE)","volume":"7 1","pages":"1-6"},"PeriodicalIF":0.0000,"publicationDate":"2018-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Detecting Violation in DiffServ Priority\",\"authors\":\"Ahmed A. Ghanem, K. Bilal\",\"doi\":\"10.1109/ICCCEEE.2018.8515848\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Due to of the fast growth in network technology structure and spread uses in all our life, in the same time the networks threated are rapidly increased. This paper presents an edge to edge model. The aim is to detect intrusion in the networks with little effort on the network resources. by monitoring and detecting the Denial of Service / Distributed Denial of Service (DoS/DDoS) attacks in case of network congestion and their impact on priority level of users. Hybrid threshold used to know if users are violating the network services or not. Random Early Detection (RED) threshold is an adaptive threshold moves between minimum and maximum values, Service Level Agreement (SLA) threshold is a predefined values determined between customer and service provider (SP). RED algorithm used in Quality of Service (QoS) DiffServ environment to monitor the network, when notice the suspicious users exceed the Hybrid threshold, the Detecting Violation in DiffServ Priority (DVDP) model moves to other phase and computes the throughput for suspicious users. This model used Network Simulator 2 (NS2) to simulate the proposed network, this network has users with low level priority triggered a lot of traffic and effected on the high level priority users and consume their bandwidth. This model detect the malicious users affected on the users have high priority, and differentiate with legal users. The accuracy on detected the malicious users estimates about 94%, and a very high sensitivity to the abnormal traffic.\",\"PeriodicalId\":6567,\"journal\":{\"name\":\"2018 International Conference on Computer, Control, Electrical, and Electronics Engineering (ICCCEEE)\",\"volume\":\"7 1\",\"pages\":\"1-6\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-08-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 International Conference on Computer, Control, Electrical, and Electronics Engineering (ICCCEEE)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCCEEE.2018.8515848\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Computer, Control, Electrical, and Electronics Engineering (ICCCEEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCEEE.2018.8515848","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
摘要
由于网络技术结构的快速发展和在我们生活中的广泛应用,与此同时,网络所面临的威胁也迅速增加。本文提出了一种边缘到边缘模型。其目的是在网络资源消耗很小的情况下检测网络中的入侵。通过监控和检测网络拥塞情况下的拒绝服务/分布式拒绝服务(DoS/DDoS)攻击及其对用户优先级的影响。混合阈值用于判断用户是否违反网络服务。RED (Random Early Detection)阈值是在最大值和最小值之间移动的自适应阈值,SLA (Service Level Agreement)阈值是客户和服务提供商(SP)之间确定的预定义值。RED算法用于QoS (Quality of Service) DiffServ环境下对网络进行监控,当注意到可疑用户超过混合阈值时,DiffServ优先级(DVDP)模型中的检测违规转移到其他阶段,计算可疑用户的吞吐量。该模型使用网络模拟器2 (NS2)来模拟所提出的网络,该网络中具有低优先级的用户触发了大量的流量并影响了高优先级的用户并消耗了他们的带宽。该模型对受影响的恶意用户进行检测,对用户具有高优先级,并与合法用户进行区分。检测到恶意用户的准确率估计在94%左右,对异常流量具有很高的敏感性。
Due to of the fast growth in network technology structure and spread uses in all our life, in the same time the networks threated are rapidly increased. This paper presents an edge to edge model. The aim is to detect intrusion in the networks with little effort on the network resources. by monitoring and detecting the Denial of Service / Distributed Denial of Service (DoS/DDoS) attacks in case of network congestion and their impact on priority level of users. Hybrid threshold used to know if users are violating the network services or not. Random Early Detection (RED) threshold is an adaptive threshold moves between minimum and maximum values, Service Level Agreement (SLA) threshold is a predefined values determined between customer and service provider (SP). RED algorithm used in Quality of Service (QoS) DiffServ environment to monitor the network, when notice the suspicious users exceed the Hybrid threshold, the Detecting Violation in DiffServ Priority (DVDP) model moves to other phase and computes the throughput for suspicious users. This model used Network Simulator 2 (NS2) to simulate the proposed network, this network has users with low level priority triggered a lot of traffic and effected on the high level priority users and consume their bandwidth. This model detect the malicious users affected on the users have high priority, and differentiate with legal users. The accuracy on detected the malicious users estimates about 94%, and a very high sensitivity to the abnormal traffic.