Ontological Classification of Network Denial of Service Attacks: Basis for a Unified Detection Framework

被引:0
|
作者
Varshovi, A. [1 ]
Sadeghiyan, B. [1 ]
机构
[1] Amirkabir Univ Technol, Dept Comp Engn & Informat Technol, Tehran, Iran
关键词
Availability; Denial of service; Detection framework; Ontology; Taxonomy; SECURITY; DEFENSE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper we introduce the notion of a detection framework to facilitate the reasoning and cooperation process of detection and response systems. The presented framework defines four dimensions as requirements to be satisfied: "What to detect", "Where to inspect", "How to decide", and "How to alert". The first dimension tries to unify the understanding of the problem between systems. The second will introduce detection features and parameters. The third dimension exactly states how intelligent systems or expert knowledge should be deployed, while the task of the fourth is to unify the alert and message exchange format. To address the "What to detect" aspect of our framework, we have considered a network denial of service and have presented an ontology which relates three taxonomies of DoS attacks, each from a different point of view: Attack Consequence, Attack Location and Attack Scenario. For scenario based taxonomy, we present a decision tree-like structure, which can be used as a base for attack detection. All these taxonomies are then related to each other in an ontology. An implementation of this ontology using Web Ontology Language (OWL) might help IETF's IDMEF to construct a base for a more accurate alert correlation.
引用
收藏
页码:133 / 148
页数:16
相关论文
共 50 条
  • [1] Ontological Classification of Network Denial of Service Attacks: Basis for a Unified Detection Framework
    Varshovi, A.
    Sadeghiyan, B.
    Scientia Iranica, 2010, 17 (2 D) : 133 - 148
  • [2] Neural Network Implementation for Detection of Denial of Service Attacks
    Topalova, Irina
    Radoyska, Pavlinka
    Sokolov, Strahil
    Journal of Engineering Science and Technology Review, 2020, (Special Issue) : 98 - 102
  • [3] An inline detection and prevention framework for distributed denial of service attacks
    Chen, Zhongqiang
    Chen, Zhongrong
    Delis, Alex
    COMPUTER JOURNAL, 2007, 50 (01): : 7 - 40
  • [4] An inline detection and prevention framework for distributed denial of service attacks
    Chen, Zhongqiang
    Chen, Zhongrong
    Delis, Alex
    Computer Journal, 2007, 50 (01): : 7 - 40
  • [5] A framework for countering denial of service attacks
    Mukkamala, S
    Sung, AH
    2004 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOLS 1-7, 2004, : 3273 - 3278
  • [6] A framework for classifying denial of service attacks
    Hussain, A
    Heidemann, J
    Papadopoulos, C
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2003, 33 (04) : 99 - 110
  • [7] A framework for the analysis of denial of service attacks
    Sharafat, AR
    Fallah, MS
    COMPUTER JOURNAL, 2004, 47 (02): : 179 - 192
  • [8] A Framework for the Analysis of Denial of Service Attacks
    Sharafat, A.R. (sharafat@isc.iranet.net), 1600, Oxford University Press (47):
  • [9] Detection of Denial-of-service Attacks
    Anh Quang Tran ZHANG Qianli LI Xing Tsinghua University Beijing China
    计算机工程, 2002, (S1) : 86 - 91
  • [10] VoIP Denial of Service Attacks Classification and Implementation
    Al-Allouni, Housam
    Rohiem, Alaa Eldin
    Ahmed, Mohammed Hashem Abd El-Aziz
    El-moghazy, Ali
    NRSC: 2009 NATIONAL RADIO SCIENCE CONFERENCE: NRSC 2009, VOLS 1 AND 2, 2009, : 434 - 445