• DocumentCode
    2304476
  • Title

    An adaptive approach to network resilience: Evolving challenge detection and mitigation

  • Author

    Yu, Yue ; Fry, Michael ; Schaeffer-Filho, Alberto ; Smith, Paul ; Hutchison, David

  • Author_Institution
    Sch. of Inf. Technol., Univ. of Sydney, Sydney, NSW, Australia
  • fYear
    2011
  • fDate
    10-12 Oct. 2011
  • Firstpage
    172
  • Lastpage
    179
  • Abstract
    It is widely agreed that computer networks need to become more resilient to a range of challenges that can seriously impact their normal operation. Challenges include malicious attacks, misconfigurations, accidental faults and operational overloads. As part of an overall strategy for network resilience, a crucial requirement is the identification of challenges in real-time, followed by the application of appropriate remedial action. In this paper, we motivate and describe a novel solution that enables the progressive multi-stage deployment of resilience strategies, based on incomplete challenge and context information. Policies are used to orchestrate the interactions between various resilience mechanisms, which incrementally identify the nature of a challenge and deploy appropriate remediation mechanisms. We demonstrate the benefits of this approach via simulation of a resource starvation attack on an Internet Service Provider infrastructure. By initially using lightweight detection and then progressively applying more heavyweight analysis, a key contribution of our work is the ability to mitigate a challenge as early as possible and rapidly detect its root cause. The approach we propose in this paper has the flexibility, reproducibility and extensibility needed to assist in the identification and remediation of various network challenges in the future.
  • Keywords
    Internet; computer network reliability; Internet service provider infrastructure; adaptive approach; computer network resilience strategy; context information policy; heavyweight analysis; lightweight detection; malicious attack; progressive multistage deployment; remedial action; remediation mechanism; resilience mechanism; resource starvation attack; Accuracy; Computer crime; Context; IP networks; Monitoring; Reliability; Resilience;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Design of Reliable Communication Networks (DRCN), 2011 8th International Workshop on the
  • Conference_Location
    Krakow
  • Print_ISBN
    978-1-61284-124-3
  • Electronic_ISBN
    978-1-61284-123-6
  • Type

    conf

  • DOI
    10.1109/DRCN.2011.6076900
  • Filename
    6076900