SIMULATION

 

Advanced Search

Journal Navigation

Journal Home

Subscriptions

Archive

Contact Us

Table of Contents

Click here to register and gain free access

Click here for more information

Sign In to gain access to subscriptions and/or personal tools.
This Article
Right arrow Full Text (PDF)
Right arrow References
Right arrow Alert me when this article is cited
Right arrow Alert me if a correction is posted
Services
Right arrow Email this article to a friend
Right arrow Similar articles in this journal
Right arrow Similar articles in ISI Web of Science
Right arrow Alert me to new issues of the journal
Right arrow Add to Saved Citations
Right arrow Download to citation manager
Right arrow Add to My Marked Citations
Citing Articles
Right arrow Citing Articles via Google Scholar
Google Scholar
Right arrow Articles by Znati, T.
Right arrow Articles by Sweeny, S.
Right arrow Search for Related Content
Social Bookmarking
 Add to CiteULike   Add to Connotea   Add to Del.icio.us   Add to Digg   Add to Reddit   Add to Technorati  
What's this?
SIMULATION, Vol. 83, No. 3, 291-303 (2007)
DOI: 10.1177/0037549707081177
© 2007 Simulation Councils Inc.

On the Design and Performance of an Adaptive, Global Strategy for Detecting and Mitigating Distributed DoS Attacks in GRID and Collaborative Workflow Environments

Taieb Znati

Department of Computer Science and Telecommunication Program University of Pittsburgh Pittsburgh PA, 15215, USA, znati{at}cs.pitt.edu

James Amadei

Department of Electrical and Computer Engineering University of Pittsburgh Pittsburgh PA, USA

Daniel R. Pazehoski

Department of Electrical and Computer Engineering University of Pittsburgh Pittsburgh PA, USA

Scott Sweeny

Department of Electrical and Computer Engineering University of Pittsburgh Pittsburgh PA, USA

While intrusion detection systems have seen a great deal of commercialization in recent years, these products are not geared towards environments, which require support for high-performance applications and open access policy for collaboration. A second limitation of existing intrusion detection systems is their lack of flexibility to deal with the ever-evolving characteristics of the attacks, in terms of diversity and intensity. Moreover, applications in high-performance collaborative environments are very diverse, with possible extreme performance requirements. Consequently, effective strategies to detect attacks in these environments strongly depend on how closely the underlying intrusion detection mechanisms reflect the "specifics" of the application. The focus of this paper is on secure GRID and workflow environments. The purpose is to investigate a distributed defense method that can secure collaborative GRID and workflow environments and neutralize attacks before they reach their potential target en mass. To this end, the paper proposes a progressive, globally deployable sentinel scheme for data sampling, packet inspection, and DoS attack detection and recovery. A simulation framework is developed to study the performance of the proposed scheme. The results show a significant improvement in how the network deals with DoS attacks to secure GRID and workflow environments, in comparison to local DoS detection and prevention schemes.

Key Words: DoS Attacks • GRID • Collaborative Workflow Environments


Add to CiteULike CiteULike   Add to Connotea Connotea   Add to Del.icio.us Del.icio.us   Add to Digg Digg   Add to Reddit Reddit   Add to Technorati Technorati    What's this?