Automating Mitigation of Amplification Attacks in NFV Services
Autor: | Matteo Repetto, Gianmarco Bruno, Jalolliddin Yusupov, Guerino Lamanna, Benjamin Ertl, Alessandro Carrega |
---|---|
Jazyk: | angličtina |
Rok vydání: | 2022 |
Předmět: | |
Zdroj: | IEEE eTransactions on network and service management (2022). info:cnr-pdr/source/autori:Matteo Repetto, Gianmarco Bruno, Jaloliddin Yusupov, Guerino Lamanna, Benjamin Ertl, and Alessandro Carrega/titolo:Automating Mitigation of Amplification Attacks in NFV Services/doi:/rivista:IEEE eTransactions on network and service management/anno:2022/pagina_da:/pagina_a:/intervallo_pagine:/volume Transactions on Network and Service Management |
Popis: | The combination of virtualization techniques with capillary computing and storage resources allows the instan- tiation of Virtual Network Functions throughout the network infrastructure, which brings more agility in the development and operation of network services. Beside forwarding and routing, this can be also used for additional functions, e.g., for security purposes. In this paper, we present a framework to systematically create security analytics for virtualized network services, specifically targeting the detection of cyber-attacks. Our framework largely automates the deployment of security sidecars into existing ser- vice templates and their interconnection to an external analytics platform. Notably, it leverages code augmentation techniques to dynamically inject and remove inspection probes without affecting service operation. We describe the implementation of a use case for the detection of DNS amplification attacks in virtualized 5G networks, and provide extensive evaluation of our innovative inspection and detection mechanisms. Our results demonstrate better efficiency with respect to existing network monitoring tools in terms of CPU usage, as well as good accuracy in detecting attacks even with variable traffic patterns. |
Databáze: | OpenAIRE |
Externí odkaz: |