A Survival Performance degrAdation fRamework for lArge-scale neTworked systems
Ricardo Macedo, Yacine M. Ghamri-Doudane, Michele Nogueira · 2017
Large scale networked systems, such as Identity Management (IdM) systems and software defined networks (SDN), have contributed to technological evolution. They simplify user and network device management. However, they strengthen Distributed Denial-of-Services (DDoS) attacks. These attacks are able to compromise system availability and harm legitimate users. The main approaches against DDoS attacks apply external resources (replication) or try to detect DDoS attacks. The first approach increases solution cost. The second is prone to high false positives. In other contexts, research into resilient approaches has increased for addressing emergent threats. In this work, we advocate that networked systems can self-manage to provide resilience. We propose a framework to guide the system design to follow the ideas defended in this thesis. The framework comprises the survival, collaboration, and analysis modules. Following the framework, networked systems can preserve their lifetime without external computer resources. The DDoS attack mitigation process starts when the system capacity overcomes a pre-established threshold. A protocol and a scheme showcase the framework over IdM systems and SDN. We conducted performance evaluations by experiments and simulations. Results show an increase in throughput and a decrease in latency of essential services when we use the proposed framework.