Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

Automating Mitigation of Amplification Attacks in NFV Services

Academic Article
Publication Date:
2022
abstract:
The combination of virtualization techniques with capillary computing and storage resources allows the instan- tiation of Virtual Network Functions throughout the network infrastructure, which brings more agility in the development and operation of network services. Beside forwarding and routing, this can be also used for additional functions, e.g., for security purposes. In this paper, we present a framework to systematically create security analytics for virtualized network services, specifically targeting the detection of cyber-attacks. Our framework largely automates the deployment of security sidecars into existing ser- vice templates and their interconnection to an external analytics platform. Notably, it leverages code augmentation techniques to dynamically inject and remove inspection probes without affecting service operation. We describe the implementation of a use case for the detection of DNS amplification attacks in virtualized 5G networks, and provide extensive evaluation of our innovative inspection and detection mechanisms. Our results demonstrate better efficiency with respect to existing network monitoring tools in terms of CPU usage, as well as good accuracy in detecting attacks even with variable traffic patterns.
Iris type:
01.01 Articolo in rivista
Keywords:
Amplification attacks; DDoS; ARIMA; eBPF; NFV; 5G
List of contributors:
Repetto, Matteo
Authors of the University:
REPETTO MATTEO
Handle:
https://iris.cnr.it/handle/20.500.14243/444518
Published in:
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT
Journal
  • Overview

Overview

URL

https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9769695
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)