Title :
Guaranteeing confidentiality in multi-domain networks: The PCE Anomaly Detector (PAD)
Author :
Gharbaoui, M. ; Paolucci, Francesco ; Giorgetti, A. ; Castoldi, Piero ; Martini, Ben
Author_Institution :
TeCIP Inst., Scuola Superiore Sant´Anna, Pisa, Italy
Abstract :
Traffic Engineering (TE) is currently required in multi-domain multi-provider networks to effectively exploit network resources. The Path Computation Element (PCE) architecture has been recently proposed for actually enabling TE in the aforementioned scenario. However, it might be exposed to several confidentiality leaks among network providers. Numerous research works in the context of multi-domain networks recently focused on authentication, authorization, and encryption mechanisms to mitigate the PCE architecture confidentiality leaks. With respect to such works, this paper tackles confidentiality issues from a different perspective, i.e., the detection of malicious utilization of path computation services aiming at inferring salient intra-domain information of other providers. This paper proposes the PCE Anomaly Detector (PAD) for detecting malicious PCE using a statistical anomaly-based approach. The novel statistical model used by the PAD is accurately described and PAD building blocks are presented. Simulation results show the effectiveness of the proposed approach that achieves an effective trade-off between the false alarms probability and the detection delay.
Keywords :
Internet; cryptography; message authentication; telecommunication traffic; Internet; PAD building blocks; PCE anomaly detector; authentication; authorization; confidentiality leaks; detection delay; encryption mechanism; false alarms probability; intradomain information; multidomain networks; network providers; path computation element; traffic engineering; Bandwidth; Computer architecture; Detectors; Monitoring; Probability; Testing; Topology; Confidentiality; Internet; Multi-domain; Multi-provider; PCE; Security; Sequential Hypothesis Testing; Traffic Engineering;
Conference_Titel :
Integrated Network Management (IM 2013), 2013 IFIP/IEEE International Symposium on
Conference_Location :
Ghent
Print_ISBN :
978-1-4673-5229-1