首页> 外文期刊>Journal of Information Recording >A Unified Ant Agent Framework for Solving DoS and QoS Problems
【24h】

A Unified Ant Agent Framework for Solving DoS and QoS Problems

机译:解决DoS和QoS问题的统一Ant Agent框架

获取原文
获取原文并翻译 | 示例
           

摘要

Anomalous traffic volume can be used for identifying network threats and faults. Denial of service (DoS) and quality of service (QoS) are two contrasting problems of anomalous network traffic. DoS exploits malicious traffic to hinder service availability to normal users, whereas QoS determines if the service provision quality has reached the preset agreement. This paper proposes a unified ant agent framework for identifying the source of these problems: IP traceback for DoS attacks and fault localization for QoS violations. Numerous studies have investigated IP traceback techniques for identifying spoofed IP addresses of attackers. These techniques can identify the attack path from the victim to the attacker. Metaheuristic algorithms that consider slight increments in traffic volume (SITV) are rarely studied for solving the IP traceback problem of DoS attacks. We investigated the malicious and nonmalicious situations for the QoS attack and QoS fault localization problem. This paper proposes a novel ant colony optimization (AGO) method for fast filtering, DoS threat source identification, and QoS fault localization (unified threat identification and fault localization by using ACO, UTFACO). The UTFACO framework was compared with the probabilistic packet marking approach and conventional ant system algorithms. We compared the efficiency of UTFACO with and without a bloom filter (BF). The framework was verified in the QoS attack and QoS fault experiment environments. This study showed that attack or fault detection and identification procedures can be designed and implemented practically. The tests used the dataset of the network topology from the DARPA repository with two cases: one is a general experiment, and the other has various levels of SITV. Perfect accuracy can be achieved for the general experiment, and more than 90% accuracy can be obtained for various levels of SITV. The datasets of the QoS attack and QoS fault were obtained from a real network. Precise fault localization is achieved due to the high detection rate obtained. The results show that UTFACO is an efficient and accurate framework. Moreover, the computation time is considerably reduced by using UTFACO with the BF, and the time is less than five seconds in the framework. Our proposed framework is robust and can solve the problem of identifying the IP address of an attacker and detecting the fault location.
机译:异常流量可以用于识别网络威胁和故障。服务拒绝(DoS)和服务质量(QoS)是网络流量异常的两个相对的问题。 DoS利用恶意流量阻碍正常用户的服务可用性,而QoS确定服务提供质量是否已达到预设协议。本文提出了一个统一的蚂蚁代理框架,用于识别这些问题的根源:用于DoS攻击的IP追溯和用于QoS违规的故障定位。许多研究调查了IP追溯技术,以识别攻击者的欺骗IP地址。这些技术可以识别从受害者到攻击者的攻击路径。很少考虑将流量略有增加的元启发式算法(SITV)来解决DoS攻击的IP回溯问题。我们针对QoS攻击和QoS故障定位问题调查了恶意和非恶意情况。本文提出了一种新的蚁群优化(AGO)方法,用于快速过滤,DoS威胁源识别和QoS故障定位(使用ACO,UTFACO进行统一的威胁识别和故障定位)。将UTFACO框架与概率数据包标记方法和传统的蚂蚁系统算法进行了比较。我们比较了有无布鲁姆滤波器(BF)的UTFACO的效率。该框架已在QoS攻击和QoS故障实验环境中进行了验证。这项研究表明,可以实际设计和实施攻击或故障检测和识别程序。这些测试使用了DARPA存储库中的网络拓扑数据集,其中有两种情况:一种是常规实验,另一种具有不同级别的SITV。对于一般实验,可以达到理想的精度,而对于不同级别的SITV,则可以达到90%以上的精度。 QoS攻击和QoS故障的数据集是从真实网络中获得的。由于获得了很高的检测率,因此可以实现精确的故障定位。结果表明,UTFACO是一个有效而准确的框架。此外,通过将UTFACO与BF一起使用,可大大减少计算时间,并且在框架中该时间少于5秒。我们提出的框架很健壮,可以解决识别攻击者的IP地址并检测故障位置的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号