Detecting Service Violations and DoS Attacks
Author
Habib, Ahsan; Hefeeda, Mohamed A.; Bhargava, Bharat K.
Entry type
techreport
Abstract
Denial of Service (DoS) attacks are a serious threat for the Internet. DoS attacks can consume memory, CPU, and network resources and damage or shut down the operation of the resource under attack (victim). The quality of service (QoS) enabled networks, which offer different levels of service, are vulnerable to QoS attacks as well as DoS attacks. The aim of a QoS attack is to steal network resources, e.g., bandwidth, or to degrade the service perceived by users. We present a classisificaton and a brief explanation of the approaches used to deal with the DoS and QoS attacks. Futhermore, we propose network monitoring techniques to detect service violations and to infer DoS attacks. Finally, a quantitative comparison among all schemes is conducted, in which, we highlight the merits of each scheme and estimate the overhead (both processing and communication) introduced by it. The comparison provides guideliness for selecting the appropriate scheme, or a combination of schemes, based on the requirements and how much overhead can be tolerated.
Date
2002
Address
Recitation Building
656 Oval Drive
West Lafayette, IN 47907
Key alpha
Habib
Number
TR 2002-15
Publisher
CERIAS Department of Computer Science
School
Purdue Universtiy
Affiliation
CERIAS and Department of Computer Sciences
Publication Date
2002-01-01
Language
English
Location
A hard-copy of this is in the CERIAS Library

