DocumentCode
2304476
Title
An adaptive approach to network resilience: Evolving challenge detection and mitigation
Author
Yu, Yue ; Fry, Michael ; Schaeffer-Filho, Alberto ; Smith, Paul ; Hutchison, David
Author_Institution
Sch. of Inf. Technol., Univ. of Sydney, Sydney, NSW, Australia
fYear
2011
fDate
10-12 Oct. 2011
Firstpage
172
Lastpage
179
Abstract
It is widely agreed that computer networks need to become more resilient to a range of challenges that can seriously impact their normal operation. Challenges include malicious attacks, misconfigurations, accidental faults and operational overloads. As part of an overall strategy for network resilience, a crucial requirement is the identification of challenges in real-time, followed by the application of appropriate remedial action. In this paper, we motivate and describe a novel solution that enables the progressive multi-stage deployment of resilience strategies, based on incomplete challenge and context information. Policies are used to orchestrate the interactions between various resilience mechanisms, which incrementally identify the nature of a challenge and deploy appropriate remediation mechanisms. We demonstrate the benefits of this approach via simulation of a resource starvation attack on an Internet Service Provider infrastructure. By initially using lightweight detection and then progressively applying more heavyweight analysis, a key contribution of our work is the ability to mitigate a challenge as early as possible and rapidly detect its root cause. The approach we propose in this paper has the flexibility, reproducibility and extensibility needed to assist in the identification and remediation of various network challenges in the future.
Keywords
Internet; computer network reliability; Internet service provider infrastructure; adaptive approach; computer network resilience strategy; context information policy; heavyweight analysis; lightweight detection; malicious attack; progressive multistage deployment; remedial action; remediation mechanism; resilience mechanism; resource starvation attack; Accuracy; Computer crime; Context; IP networks; Monitoring; Reliability; Resilience;
fLanguage
English
Publisher
ieee
Conference_Titel
Design of Reliable Communication Networks (DRCN), 2011 8th International Workshop on the
Conference_Location
Krakow
Print_ISBN
978-1-61284-124-3
Electronic_ISBN
978-1-61284-123-6
Type
conf
DOI
10.1109/DRCN.2011.6076900
Filename
6076900
Link To Document