The Experts below are selected from a list of 165296115 Experts worldwide ranked by ideXlab platform
Ashraf Matrawy - One of the best experts on this subject based on the ideXlab platform.
-
CNS - Towards Secure Slicing: Using Slice Isolation to Mitigate DDoS Attacks on 5G Core Network Slices
2019 IEEE Conference on Communications and Network Security (CNS), 2019Co-Authors: Danish Sattar, Ashraf MatrawyAbstract:In this paper, we propose a solution to proactively mitigate Distributed Denial-of-Service attacks in 5G core network slicing using slice isolation. Network slicing is one of the key technologies that allow 5G networks to offer dedicated resources to different industries (services). However, a Distributed Denial-of-Service attack could severely impact the performance and availability of the slices as they could share the same physical resources in a multi-tenant virtualized networking infrastructure. Slice isolation is an essential requirement for 5G network slicing. In this paper, we use network isolation to tackle the challenging problem of Distributed Denial-of-Service attacks in 5G network slicing. We propose the use of a mathematical model that can provide on-demand slice isolation as well as guarantee end-to-end delay for 5G core network slices. We evaluate the proposed work with a mix of simulation and experimental work. Our results show that the proposed isolation could mitigate Distributed Denial-of-Service attacks as well as increase the availability of the slices. We believe this work will encourage further research in securing 5G network slicing.
-
towards secure slicing using slice isolation to mitigate ddos attacks on 5g core network slices
arXiv: Networking and Internet Architecture, 2019Co-Authors: Danish Sattar, Ashraf MatrawyAbstract:In this paper, we propose a solution to proactively mitigate Distributed Denial-of-Service attacks in 5G core network slicing using slice isolation. Network slicing is one of the key technologies that allow 5G networks to offer dedicated resources to different industries (services). However, a Distributed Denial-of-Service attack could severely impact the performance and availability of the slices as they could share the same physical resources in a multi-tenant virtualized networking infrastructure. Slice isolation is an essential requirement for 5G network slicing. In this paper, we use network isolation to tackle the challenging problem of Distributed Denial-of-Service attacks in 5G network slicing. We propose the use of a mathematical model that can provide on-demand slice isolation as well as guarantee end-to-end delay for 5G core network slices. We evaluate the proposed work with a mix of simulation and experimental work. Our results show that the proposed isolation could mitigate Distributed Denial-of-Service attacks as well as increase the availability of the slices. We believe this work will encourage further research in securing 5G network slicing.
Danish Sattar - One of the best experts on this subject based on the ideXlab platform.
-
CNS - Towards Secure Slicing: Using Slice Isolation to Mitigate DDoS Attacks on 5G Core Network Slices
2019 IEEE Conference on Communications and Network Security (CNS), 2019Co-Authors: Danish Sattar, Ashraf MatrawyAbstract:In this paper, we propose a solution to proactively mitigate Distributed Denial-of-Service attacks in 5G core network slicing using slice isolation. Network slicing is one of the key technologies that allow 5G networks to offer dedicated resources to different industries (services). However, a Distributed Denial-of-Service attack could severely impact the performance and availability of the slices as they could share the same physical resources in a multi-tenant virtualized networking infrastructure. Slice isolation is an essential requirement for 5G network slicing. In this paper, we use network isolation to tackle the challenging problem of Distributed Denial-of-Service attacks in 5G network slicing. We propose the use of a mathematical model that can provide on-demand slice isolation as well as guarantee end-to-end delay for 5G core network slices. We evaluate the proposed work with a mix of simulation and experimental work. Our results show that the proposed isolation could mitigate Distributed Denial-of-Service attacks as well as increase the availability of the slices. We believe this work will encourage further research in securing 5G network slicing.
-
towards secure slicing using slice isolation to mitigate ddos attacks on 5g core network slices
arXiv: Networking and Internet Architecture, 2019Co-Authors: Danish Sattar, Ashraf MatrawyAbstract:In this paper, we propose a solution to proactively mitigate Distributed Denial-of-Service attacks in 5G core network slicing using slice isolation. Network slicing is one of the key technologies that allow 5G networks to offer dedicated resources to different industries (services). However, a Distributed Denial-of-Service attack could severely impact the performance and availability of the slices as they could share the same physical resources in a multi-tenant virtualized networking infrastructure. Slice isolation is an essential requirement for 5G network slicing. In this paper, we use network isolation to tackle the challenging problem of Distributed Denial-of-Service attacks in 5G network slicing. We propose the use of a mathematical model that can provide on-demand slice isolation as well as guarantee end-to-end delay for 5G core network slices. We evaluate the proposed work with a mix of simulation and experimental work. Our results show that the proposed isolation could mitigate Distributed Denial-of-Service attacks as well as increase the availability of the slices. We believe this work will encourage further research in securing 5G network slicing.
Abusayeed Saifullah - One of the best experts on this subject based on the ideXlab platform.
-
Defending against Distributed Denial-of-Service Attacks with Weight-Fair Router Throttles
2014Co-Authors: Abusayeed SaifullahAbstract:Abstract—A high profile internet server is always a target of Denial-of-Service attacks. In this project, we propose a novel technique for protecting an internet server from distributed Denial-of-Service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server are controlled (increased or decreased) by the leaky-buckets at the routers based on the number of users connected, directly or through other routers, to each router. To the best of our knowledge, this is the first weightfair technique for saving an internet server from Denial-of-Service attacks. The system is guaranteed to work even if some of the routers are compromised. Furthermore, in the beginning of the algorithm, the server’s capacity is underestimated by the routers so as to protect the server from any sudden initial attack. Keywords-Network security; Distributed Denial-of-Service attack; Internet server; I
-
Defending Against Distributed Denial-of-Service Attacks With Weight-Fair Router Throttling
2009Co-Authors: Abusayeed SaifullahAbstract:A high profile internet server is always a target of Denial-of-Service attacks. In this paper, we propose a novel technique for protecting an internet server from distributed Denial-of-Service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server are controlled increased or decreased ) by the leaky-buckets at the routers based on the number of users connected, directly or through other routers, to each router. To the best of our knowledge, this is the first weight-fair technique for saving an internet server from Denial-of-Service attacks. The system is guaranteed to work even if some of the routers are compromised. Furthermore, in the beginning of the algorithm, the server’s capacity is underestimated by the routers so as to protect the server from any sudden initial attack. Type of Report: Other Department of Computer Science & Engineering Washington University in St. Louis Campus Box 1045 St. Louis, MO 63130 ph: (314) 935-6160 Defending Against Distributed Denial-of-Service Attacks With Weight-Fair Router Throttling Abusayeed M Saifullah Computer Science and Engineering Washington University in St. Louis St. Louis, MO 63130 USA Email: saifullaha@cse.wustl.edu ABSTRACT A high profile internet server is always a target of Denial-of-Service attacks. In this paper, we propose a novel technique for protecting an internet server from distributed Denial-of-Service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server are controlled (increased or decreased ) by the leaky-buckets at the routers based on the number of users connected, directly or through other routers, to each router. To the best of our knowledge, this is the first weight-fair technique for saving an internet server from Denial-of-Service attacks. The system is guaranteed to work even if some of the routers are compromised. Furthermore, in the beginning of the algorithm, the server’s capacity is underestimated by the routers so as to protect the server from any sudden initial attack.A high profile internet server is always a target of Denial-of-Service attacks. In this paper, we propose a novel technique for protecting an internet server from distributed Denial-of-Service attacks. The defense mechanism is based on a distributed algorithm that performs weight-fair throttling at the upstream routers. The throttling is weight-fair because the traffics destined for the server are controlled (increased or decreased ) by the leaky-buckets at the routers based on the number of users connected, directly or through other routers, to each router. To the best of our knowledge, this is the first weight-fair technique for saving an internet server from Denial-of-Service attacks. The system is guaranteed to work even if some of the routers are compromised. Furthermore, in the beginning of the algorithm, the server’s capacity is underestimated by the routers so as to protect the server from any sudden initial attack.
Kotagiri Ramamohanarao - One of the best experts on this subject based on the ideXlab platform.
-
survey of network based defense mechanisms countering the dos and ddos problems
ACM Computing Surveys, 2007Co-Authors: Tao Peng, Christopher Leckie, Kotagiri RamamohanaraoAbstract:This article presents a survey of denial of service attacks and the methods that have been proposed for defense against these attacks. In this survey, we analyze the design decisions in the Internet that have created the potential for denial of service attacks. We review the state-of-art mechanisms for defending against denial of service attacks, compare the strengths and weaknesses of each proposal, and discuss potential countermeasures against each defense mechanism. We conclude by highlighting opportunities for an integrated solution to solve the problem of distributed denial of service attacks.
Chun-kan Fung - One of the best experts on this subject based on the ideXlab platform.
-
SMARTNET - A Client Puzzle Based Public-key Authentication Protocol
Smart Networks, 2002Co-Authors: Chun-kan Fung, M Y WongAbstract:Network Denial-of-Service attacks, which exhaust the server resources, have become a serious security threat to the Internet. Public Key Infrastructure (PKI) has long been introduced in various authentication protocols to verify the identities of the communicating parties. Although the use of PKI can present difficulty to the Denial-of-Service attackers, the underlying problem has not been resolved completely, because the use of public-key infrastructure involves computationally expensive operations such as modular exponentiation. An improper deployment of the public-key operations in a protocol allows the attacker to exhaust the server’s resources. This paper presents a public-key based authentication protocol integrated with a sophisticated client puzzle, which together provides a good solution for network Denial-of-Service attacks, and various other common attacks. The basic strategy to protect against denial of service is to impose an adjustable cost on the attacker while it launches the attacks. The proposed client puzzle protocol can also be integrated with other network protocols to protect against Denial-of-Service attacks.
-
A Denial-of-Service resistant public-key authentication and key establishment protocol
Conference Proceedings of the IEEE International Performance Computing and Communications Conference (Cat. No.02CH37326), 2002Co-Authors: Chun-kan FungAbstract:Network Denial-of-Service attacks, which exhaust the server resources, have become a serious security threat to the Internet. Public key infrastructure (PKI) has long been introduced in various authentication protocols to verify the identities of the communicating parties. Although the use of PKI can present difficulty to the Denial-of-Service attackers, the underlying problem has not been resolved completely, because the use of public-key infrastructure involves computationally expensive operations such as modular exponentiation. An improper deployment of the public-key operations in a protocol allows the attacker to exhaust the server's resources. This paper presents a public-key based authentication and key establishment protocol integrated with a sophisticated client puzzle, which together provides a good solution for network Denial-of-Service attacks, and various other common attacks. The joint establishment of session keys by both the client and the server protects the session after the mutual authentication. The basic strategy to protect against denial of service is to impose an adjustable cost on the attacker while launching the attacks. The proposed client puzzle protocol can also be integrated with other network protocols to protect against Denial-of-Service attacks.