Tool support for the evaluation of anomaly traffic classification for network resilience

da Silva, Anderson and Wickboldt, Juliano and Schaeffer-Filho, Alberto and Marnerides, Angelos and Mauthe, Andreas Ulrich (2015) Tool support for the evaluation of anomaly traffic classification for network resilience. In: Proceedings of 20th IEEE Symposium on Computers and Communications, ISCC2015. IEEE, pp. 514-519. ISBN 9781467371957

[img]
Preview
PDF (ISCC_PRESET)
ISCC_PRESET.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (437kB)

Abstract

Resilience is the ability of the network to maintain an acceptable level of operation in the face of anomalies, such as malicious attacks, operational overload or misconfigurations. Techniques for anomaly traffic classification are often used to characterize suspicious network traffic, thus supporting anomaly detection schemes in network resilience strategies. In this paper, we extend the PReSET toolset to allow the investigation, comparison and analysis of algorithms for anomaly traffic classification based on machine learning. PReSET was designed to allow the simulation-based evaluation of resilience strategies, thus enabling the comparison of optimal configurations and policies for combating different types of attacks (e.g., DDoS attacks, worms) and other anomalies. In such resilience strategies, policies written in the Ponder2 language can be used to activate/reconfigure traffic classification modules and other mechanisms (e.g., traffic shaping), depending on monitored results in the simulation environment. Our results show that PReSET can be a valuable tool for network operators to evaluate anomaly traffic classification techniques in terms of standard performance metrics.

Item Type:
Contribution in Book/Report/Proceedings
Additional Information:
©2015 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
ID Code:
78013
Deposited By:
Deposited On:
28 Jan 2016 13:28
Refereed?:
Yes
Published?:
Published
Last Modified:
29 Mar 2020 00:21