Ontological Classification of Network Denial of Service Attacks: Basis for a Unified Detection Framework

被引:0
|
作者
Varshovi, A. [1 ]
Sadeghiyan, B. [1 ]
机构
[1] Amirkabir Univ Technol, Dept Comp Engn & Informat Technol, Tehran, Iran
关键词
Availability; Denial of service; Detection framework; Ontology; Taxonomy; SECURITY; DEFENSE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper we introduce the notion of a detection framework to facilitate the reasoning and cooperation process of detection and response systems. The presented framework defines four dimensions as requirements to be satisfied: "What to detect", "Where to inspect", "How to decide", and "How to alert". The first dimension tries to unify the understanding of the problem between systems. The second will introduce detection features and parameters. The third dimension exactly states how intelligent systems or expert knowledge should be deployed, while the task of the fourth is to unify the alert and message exchange format. To address the "What to detect" aspect of our framework, we have considered a network denial of service and have presented an ontology which relates three taxonomies of DoS attacks, each from a different point of view: Attack Consequence, Attack Location and Attack Scenario. For scenario based taxonomy, we present a decision tree-like structure, which can be used as a base for attack detection. All these taxonomies are then related to each other in an ontology. An implementation of this ontology using Web Ontology Language (OWL) might help IETF's IDMEF to construct a base for a more accurate alert correlation.
引用
收藏
页码:133 / 148
页数:16
相关论文
共 50 条
  • [21] On Detection and Mitigation of Slow Rate Denial of Service Attacks
    Sikora, Marek
    Gerlich, Tomas
    Malina, Lukas
    2019 11TH INTERNATIONAL CONGRESS ON ULTRA MODERN TELECOMMUNICATIONS AND CONTROL SYSTEMS AND WORKSHOPS (ICUMT), 2019,
  • [22] Detection of denial of service attacks using neural networks
    Bolanos, RF
    Cadena, CA
    Nino, F
    6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL X, PROCEEDINGS: MOBILE/WIRELESS COMPUTING AND COMMUNICATION SYSTEMS II, 2002, : 84 - 87
  • [23] A Novel Mechanism for Detection of Distributed Denial of Service Attacks
    Sen, Jaydip
    ADVANCED COMPUTING, PT III, 2011, 133 : 247 - 257
  • [24] Detection and Prevention of Distributed Denial of Service Attacks in VANETs
    Shabbir, Munazza
    Khan, Muazzam A.
    Khan, Umair Shafiq
    Saqib, Nazar A.
    2016 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE & COMPUTATIONAL INTELLIGENCE (CSCI), 2016, : 970 - 974
  • [25] A mechanism for detection and prevention of distributed denial of service attacks
    Sen, Jaydip
    Chowdhury, Piyali Roy
    Sengupta, Indranil
    DISTRIBUTED COMPUTING AND NETWORKING, PROCEEDINGS, 2006, 4308 : 139 - 144
  • [26] Toward lightweight detection and visualization for denial of service attacks
    Kim, Dong Seong
    Lee, Sang Min
    Park, Jong Son
    MICAI 2006: ADVANCES IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2006, 4293 : 632 - +
  • [27] Experiments on Detection of Denial of Service Attacks using REPTree
    Katkar, Vijay D.
    Bhatia, Deepti S.
    2013 INTERNATIONAL CONFERENCE ON GREEN COMPUTING, COMMUNICATION AND CONSERVATION OF ENERGY (ICGCE), 2013, : 713 - 718
  • [28] A Review on Detection Approaches for Distributed Denial of Service Attacks
    Chaudhari, Rutika S.
    Talmale, G. R.
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INTELLIGENT SUSTAINABLE SYSTEMS (ICISS 2019), 2019, : 323 - 327
  • [29] Effectiveness and Detection of Denial-of-Service Attacks in Tor
    Danner, Norman
    Defabbia-Kane, Sam
    Krizanc, Danny
    Liberatore, Marc
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2012, 15 (03)
  • [30] Detection of Denial-of-Service Attacks with SNMP/RMON
    Boyar, O.
    Ozen, M. E.
    Metin, B.
    2018 IEEE 22ND INTERNATIONAL CONFERENCE ON INTELLIGENT ENGINEERING SYSTEMS (INES 2018), 2018, : 437 - 440