The Experts below are selected from a list of 619584 Experts worldwide ranked by ideXlab platform
Selvakumar Manickam - One of the best experts on this subject based on the ideXlab platform.
-
improved mechanism to prevent denial of service Attack in ipv6 duplicate address detection process
International Journal of Advanced Computer Science and Applications, 2017Co-Authors: Shafiq Ur Rehman, Selvakumar ManickamAbstract:From the days of ARPANET, with slightly over two hundred connected hosts involving five organizations to a massive global, always-on network connecting hosts in the billions, the Internet has become as important as the need for electricity and water. Internet Protocol version 4 (IPv4) could not sustain the growth of the Internet. In ensuring the growth is not stunted, a new protocol, i.e. Internet Protocol version 6 (IPv6) was introduced that resolves the addressing issue IPv4 had. In addition, IPv6 was also laden with new features and capabilities. One of them being address auto-configuration. This feature allows hosts to self-configure without the need for additional services. Nevertheless, the design of IPv6 has led to several security shortcomings. Duplicate Address Detection (DAD) process required for auto-configuration is prone to Denial of Service (DoS) Attack in which hosts are unable to configure themselves to join the network. Various mechanisms, SeND, SSAS, and the most recent being Trust-ND, have been introduced to address this issue. Although these mechanisms were able to circumvent DoS Attack on DAD process, they have introduced various side effects, i.e. complexities and degradation of performance. This paper reviews the shortcomings of these mechanism and proposes a new mechanism, Secure-DAD, that addresses them. The performance comparison between Trust-ND and Secure-ND also showed that Secure-DAD is more promising with improvement in terms of processing time reduction of 45.1% compared to Trust-ND while preventing DoS Attack in IPv6 DAD process.
-
denial of service Attack in ipv6 duplicate address detection process
International Journal of Advanced Computer Science and Applications, 2016Co-Authors: Shafiq Ur Rehman, Selvakumar ManickamAbstract:IPv6 was designed to replace the existing Internet Protocol, that is, IPv4. The main advantage of IPv6 over IPv4 is the vastness of address space. In addition, various improvements were brought to IPv6 to address the drawbacks in IPv4. Nevertheless, as with any new technology, IPv6 suffers from various security vulnerabilities. One of the vulnerabilities discovered allows Denial of Service Attack using the Duplicate Address Detection mechanism. In order to study and analyse this Attack, an IPv6 security testbed was designed and implemented. This paper presents our experience with the deployment and operation of the testbed, and discussion on the outcome and data gathered from carrying out DoS Attack in this testbed
Ling Shi - One of the best experts on this subject based on the ideXlab platform.
-
optimal denial of service Attack scheduling with energy constraint over packet dropping networks
IEEE Transactions on Automatic Control, 2018Co-Authors: Jiahu Qin, Ling ShiAbstract:The recent years have seen a surge of security issues of cyber-physical systems (CPS). In this paper, Denial-of-Service (DoS) Attack scheduling is investigated in depth. Specifically, we consider a system where a remote estimator receives the data packet sent by a sensor over a wireless network at each time instant, and an energy-constrained Attacker that cannot launch DoS Attacks all the time designs the optimal DoS Attack scheduling to maximize the Attacking effect on the remote estimation performance. Most of the existing works concerning DoS Attacks focus on the ideal scenario in which data packets can be received successfully if there is no DoS Attack. To capture the unreliability nature of practical networks, we study the packet-dropping network in which packet dropouts may occur even in the absence of Attack. We derive the optimal Attack scheduling scheme that maximizes the average expected estimation error, and the one which maximizes the expected terminal estimation error over packet-dropping networks. We also present some countermeasures against DoS Attacks, and discuss the optimal defense strategy, and how the optimal Attack schedule can serve for more effective and resource-saving countermeasures. We further investigate the optimal Attack schedule with multiple sensors. The optimality of the theoretical results is demonstrated by numerical simulations.
-
optimal denial of service Attack scheduling with energy constraint
IEEE Transactions on Automatic Control, 2015Co-Authors: Heng Zhang, Ling Shi, Peng Cheng, Jiming ChenAbstract:Security of Cyber-Physical Systems (CPS) has gained increasing attention in recent years. Most existing works mainly investigate the system performance given some Attacking patterns. In this technical note, we investigate how an Attacker should schedule its Denial-of-Service (DoS) Attacks to degrade the system performance. Specifically, we consider the scenario where a sensor sends its data to a remote estimator through a wireless channel, while an energy-constrained Attacker decides whether to jam the channel at each sampling time. We construct optimal Attack schedules to maximize the expected average estimation error at the remote estimator. We also provide the optimal Attack schedules when a special intrusion detection system (IDS) at the estimator is given. We further discuss the optimal Attack schedules when the sensor has energy constraint. Numerical examples are presented to demonstrate the effectiveness of the proposed optimal Attack schedules.
-
optimal denial of service Attack scheduling against linear quadratic gaussian control
Advances in Computing and Communications, 2014Co-Authors: Heng Zhang, Ling Shi, Peng Cheng, Jiming ChenAbstract:Recently a flood of literature concerned on the security issues of wireless networked control system. However, it is still lack of investigation on how the Attacker should optimize its Attack schedule in order to maximize the effect on the system performance due to the insufficiency of energy at the Attacker side. This paper fills this gap from the aspect of control system performance. Especially, this paper investigates the optimal jamming Attack which maximizes the linear quadratic Gaussian control cost function under energy constraint. After analyzing the properties of the cost function under an arbitrary Attack schedule, we derive the optimal jamming Attack schedule and the corresponding cost function. System stability under this optimal Attack schedule is also considered. Different examples are provided to demonstrate the effectiveness of the proposed optimal jamming schedule.
Minho Park - One of the best experts on this subject based on the ideXlab platform.
-
efficient distributed denial of service Attack defense in sdn based cloud
IEEE Access, 2019Co-Authors: Trung V Phan, Minho ParkAbstract:Software-defined networking (SDN) is the key outcome of extensive research efforts over the past few decades toward transforming the Internet infrastructure to be more programmable, configurable, and manageable. However, critical cyber-threats in the SDN-based cloud environment are rising rapidly, in which distributed Denial-of-Service (DDoS) Attack is one of the most damaging cyber Attacks. In this paper, we propose an efficient solution to tackle DDoS Attacks in the SDN-based cloud environment. We first introduce a new hybrid machine learning model based on support vector machine and self-organizing map algorithms to improve the traffic classification. Then, we propose an enhanced history-based IP filtering scheme ( $eHIPF$ ) to improve the Attack detection rate and speed. Finally, we introduce a novel mechanism that combines both the hybrid machine learning model and the $eHIPF$ scheme to make a DDoS Attack defender for the SDN-based cloud environment. The testbed is implemented in an SDN-based cloud with service function chaining. Through practical experiments, the proposed DDoS Attack defender is proven to outperform existing mechanisms for DDoS Attack classification and detection. The comprehensive experiments conducted with various DDoS Attack levels prove that the proposed mechanism is an effective, innovative approach to defend DDoS Attacks in the SDN-based cloud.
Shafiq Ur Rehman - One of the best experts on this subject based on the ideXlab platform.
-
improved mechanism to prevent denial of service Attack in ipv6 duplicate address detection process
International Journal of Advanced Computer Science and Applications, 2017Co-Authors: Shafiq Ur Rehman, Selvakumar ManickamAbstract:From the days of ARPANET, with slightly over two hundred connected hosts involving five organizations to a massive global, always-on network connecting hosts in the billions, the Internet has become as important as the need for electricity and water. Internet Protocol version 4 (IPv4) could not sustain the growth of the Internet. In ensuring the growth is not stunted, a new protocol, i.e. Internet Protocol version 6 (IPv6) was introduced that resolves the addressing issue IPv4 had. In addition, IPv6 was also laden with new features and capabilities. One of them being address auto-configuration. This feature allows hosts to self-configure without the need for additional services. Nevertheless, the design of IPv6 has led to several security shortcomings. Duplicate Address Detection (DAD) process required for auto-configuration is prone to Denial of Service (DoS) Attack in which hosts are unable to configure themselves to join the network. Various mechanisms, SeND, SSAS, and the most recent being Trust-ND, have been introduced to address this issue. Although these mechanisms were able to circumvent DoS Attack on DAD process, they have introduced various side effects, i.e. complexities and degradation of performance. This paper reviews the shortcomings of these mechanism and proposes a new mechanism, Secure-DAD, that addresses them. The performance comparison between Trust-ND and Secure-ND also showed that Secure-DAD is more promising with improvement in terms of processing time reduction of 45.1% compared to Trust-ND while preventing DoS Attack in IPv6 DAD process.
-
denial of service Attack in ipv6 duplicate address detection process
International Journal of Advanced Computer Science and Applications, 2016Co-Authors: Shafiq Ur Rehman, Selvakumar ManickamAbstract:IPv6 was designed to replace the existing Internet Protocol, that is, IPv4. The main advantage of IPv6 over IPv4 is the vastness of address space. In addition, various improvements were brought to IPv6 to address the drawbacks in IPv4. Nevertheless, as with any new technology, IPv6 suffers from various security vulnerabilities. One of the vulnerabilities discovered allows Denial of Service Attack using the Duplicate Address Detection mechanism. In order to study and analyse this Attack, an IPv6 security testbed was designed and implemented. This paper presents our experience with the deployment and operation of the testbed, and discussion on the outcome and data gathered from carrying out DoS Attack in this testbed
Jiming Chen - One of the best experts on this subject based on the ideXlab platform.
-
optimal denial of service Attack scheduling with energy constraint
IEEE Transactions on Automatic Control, 2015Co-Authors: Heng Zhang, Ling Shi, Peng Cheng, Jiming ChenAbstract:Security of Cyber-Physical Systems (CPS) has gained increasing attention in recent years. Most existing works mainly investigate the system performance given some Attacking patterns. In this technical note, we investigate how an Attacker should schedule its Denial-of-Service (DoS) Attacks to degrade the system performance. Specifically, we consider the scenario where a sensor sends its data to a remote estimator through a wireless channel, while an energy-constrained Attacker decides whether to jam the channel at each sampling time. We construct optimal Attack schedules to maximize the expected average estimation error at the remote estimator. We also provide the optimal Attack schedules when a special intrusion detection system (IDS) at the estimator is given. We further discuss the optimal Attack schedules when the sensor has energy constraint. Numerical examples are presented to demonstrate the effectiveness of the proposed optimal Attack schedules.
-
optimal denial of service Attack scheduling against linear quadratic gaussian control
Advances in Computing and Communications, 2014Co-Authors: Heng Zhang, Ling Shi, Peng Cheng, Jiming ChenAbstract:Recently a flood of literature concerned on the security issues of wireless networked control system. However, it is still lack of investigation on how the Attacker should optimize its Attack schedule in order to maximize the effect on the system performance due to the insufficiency of energy at the Attacker side. This paper fills this gap from the aspect of control system performance. Especially, this paper investigates the optimal jamming Attack which maximizes the linear quadratic Gaussian control cost function under energy constraint. After analyzing the properties of the cost function under an arbitrary Attack schedule, we derive the optimal jamming Attack schedule and the corresponding cost function. System stability under this optimal Attack schedule is also considered. Different examples are provided to demonstrate the effectiveness of the proposed optimal jamming schedule.