<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Novas propostas com avaliações de técnicas preventivas e reativas contra ataques na internet e redes de próxima geração

Carregando...
Imagem de Miniatura

Título da Revista

ISSN da Revista

Título de Volume

Editor

Universidade Federal do Rio de Janeiro

DOI

Resumo

Cyberattacks challenge the evolution of next-generation communication networks such as 5G and 6G. To defend themselves and their customers, service providers have invested in traditional detection and mitigation systems. Although they are e cient, these systems have problems, inducing incorrect decisions, which can compromise legitimate tra c. The Defense-in-Depth strategy o ers new approaches, hampering the attack progression through multiple lines of defense. This thesis presents two advanced systems for detecting and mitigating cyberattacks. The distributed intrusion detection system is based on the BGP network to create a federation of agents, which cooperate with each other to alarm malicious ows in the Internet. Performance metrics obtained analytically, combining data fusion with Bayesian inference, show results comparable to the best systems. This proposed modeling can even be used to assess the performance of similar distributed systems. To prevent attacks against the detection platform itself, it is proposed a machine learning system to infer the reputation of BGP advertisements. Tests based on a dataset with 15 attributes extracted individually from the message headers show that it is possible to learn with accuracy above 90%. In the mitigation part, a system based on Game Theory is presented to con ne the e ects of denial of service attacks. The resource scaling engine uses the virtualized environment of the 5G control plane to balance tra c, preventing the immediate exhaustion caused by the attack and stopping it by deterrence. Performance tests using a queuing model demonstrate that the system is able to reduce the load by up to 20% at each scaling level.

Descrição

Citação

SILVA, Renato Souza. Novas propostas com avaliações de técnicas preventivas e reativas contra ataques na internet e redes de próxima geração. 2021. 172 f. Tese (Doutorado) - Programa de Pós-Graduação em Engenharia de Sistemas e Computação, COPPE, Universidade Federal do Rio de Janeiro, Rio de Janeiro, 2021.

Avaliação

Revisão

Suplementado Por

Referenciado Por

Direitos e licensiamento

Acesso Aberto