• DocumentCode
    3694401
  • Title

    Mitigating DoS attacks in identity management systems through reorganizations

  • Author

    Ricardo Macedo;Yacine Ghamri-Doudane;Michele Nogueira

  • Author_Institution
    NR2 - Federal University of Paraná
  • fYear
    2015
  • Firstpage
    27
  • Lastpage
    34
  • Abstract
    Ensuring identity management (IdM) systems availability plays a key role to support networked systems. Denial-of-Service (DoS) attacks can make IdM operations unavailable, preventing the use of computational resources by legitimate users. In the literature, the main countermeasures against DoS over IdM systems are based on either the application of external resources to extend the system lifetime (replication) or on DoS attacks detection. The first approach increases the solutions cost, and in general the second approach is still prone to high rates of false negatives and/or false positives. Hence, this work presents SAMOS, a novel and paradigm-shifting Scheme for DoS Attacks Mitigation by the reOrganization and optimization of the IdM System. SAMOS optimizes the reorganization of the IdM system components founded on optimization techniques, minimizing DoS effects and improving the system lifetime. SAMOS is based on the unavailabilities effects such as the exhaustion of processing and memory resources, eliminating the dependence of attacks detection. Furthermore, SAMOS employs operational IdPs from the IdM system to support the demand of the IdM system, differently from replication approaches. Results considering data from two real IdM systems indicate the scheme viability and improvements. As future works, SAMOS will be prototyped in order to allow performance evaluations in a real testbed.
  • Keywords
    "Computer crime","Optimization","Authentication","IP networks","Cloud computing","Proposals"
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (LANOMS), 2015 Latin American
  • Type

    conf

  • DOI
    10.1109/LANOMS.2015.7332666
  • Filename
    7332666