An adaptive mitigation framework for handling suspicious network flows via MPLS policies

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

As network attacks become more complex, defence strategies must provide means to handle more flexible and dynamic requirements. The Multiprotocol Label Switching (MPLS) standard is a promising method to properly handle suspicious flows participating in such network attacks. Tasks such as alert data extraction, and MPLS routers configuration present an entailment to activate the defence process. This paper introduces a novel framework to define, generate and implement mitigation policies on MPLS routers. The activation of such policies is triggered by the alerts and expressed using a high level formalism. An implementation of the approach is presented.

Original languageEnglish
Title of host publicationSecure IT Systems - 18th Nordic Conference, NordSec 2013, Proceedings
PublisherSpringer Verlag
Pages297-312
Number of pages16
ISBN (Print)9783642414879
DOIs
Publication statusPublished - 1 Jan 2013
Externally publishedYes
Event18th Nordic Conference on Secure IT Systems, NordSec 2013 - Ilulissat, Greenland
Duration: 18 Oct 201321 Oct 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8208 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th Nordic Conference on Secure IT Systems, NordSec 2013
Country/TerritoryGreenland
CityIlulissat
Period18/10/1321/10/13

Keywords

  • MPLS
  • Network Security
  • OrBAC
  • Policy Management

Fingerprint

Dive into the research topics of 'An adaptive mitigation framework for handling suspicious network flows via MPLS policies'. Together they form a unique fingerprint.

Cite this