• Home
  • Search
  • Layer-4 service differentiation and resource isolation
  • Cite Icon10
  • https://doi.org/10.1109/rttas.2002.1137382Copy DOI Icon

Layer-4 service differentiation and resource isolation

  • Sep 25, 2002
  • Haining Wang +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

While the differentiated services (DiftServ) infrastructure is scalable and robust in providing network quality of service (QoS), there are serious drawbacks with the services provided by DiffServ: (1) the services are coarse-grained and one-way only; (2) no service differentiation and resource isolation are provided to meta-data packets such as TCP SYN and ACK packets. Moreover the coarse-grained service differentiation and the lack of resource isolation at IP routers exposes its vulnerability to distributed denial of service (DDoS) attacks. Based on the concept of layer-4 service differentiation and resource isolation, where the transport-layer information is inferred from the IP headers and used for packet classification and resource management, we present a scalable fine-grained DiffServ (sf-DiffServ) architecture that provides fine-grained service differentiation and resource isolation among thinner behavior aggregates (BAs). The sf-DiffServ architecture consists of a fine-grained QoS classifier and an adaptive weight-based resource manager at IP routers. A two-stage packet classification mechanism is devised to decouple the fine-grained QoS lookup from the routing lookup at core routers. Due to its scalable QoS support for TCP control segments, sf-DiffServ supports bi-directional differentiated services for TCP sessions. Most importantly, the fine-grained resource isolation provided inside the sf-DiffServ is a powerful built-in protection mechanism to counter DDoS attacks, reducing the vulnerability of the Internet to DDoS attacks.

Similar Papers
  • Book Chapter
  • Citations35

DARAC: DDoS Mitigation Using DDoS Aware Resource Allocation in Cloud

  • Jan 01, 2015
  • Gaurav Somani +5
  • Conference Article
  • Citations3

Secure Network Slice Mapping Strategy for Security and Stability Control System

  • Dec 09, 2022
  • Kaiqiang Gao +6
  • Conference Article
  • Citations2

Notice of Violation of IEEE Publication Principles: An Effective Defense against Distributed Denial of Service in Grid

  • Aug 01, 2010
  • 2010 First International Conference on Integrated Intelligent Computing
  • H S Mohan +1
  • Research Article

Ключевые характеристики сетевого трафика для идентификации DDoS-атаки

  • Jan 01, 2024
  • LETI Transactions on Electrical Engineering & Computer Science
  • R R Fatkieva +2
  • Research Article

AI Driven Context-Aware DDoS Detection and Mitigation Framework Using Optimized CNN–BiLSTM and Reinforcement Learning

  • Jan 19, 2026
  • International Journal on Advanced Electrical and Computer Engineering
  • Mahesh S Rathod +2
  • Research Article
  • Citations49

Review of Detection DDOS Attack Detection Using Naive Bayes Classifier for Network Forensics

  • Jun 01, 2017
  • Bulletin of Electrical Engineering and Informatics
  • Abdul Fadlil +2
  • PDF
  • Research Article
  • Citations3

Securing Cloud Computing Services with an Intelligent Preventive Approach

  • Jun 01, 2024
  • Engineering, Technology & Applied Science Research
  • Saleh M Altowaijri +1
  • Research Article
  • Citations20

The Slow HTTP Distributed Denial of Service Attack Detection in Cloud

  • May 02, 2019
  • Scalable Computing: Practice and Experience
  • A Dhanapal +1
  • Conference Article
  • Citations33

Detecting Flooding-Based DDoS Attacks

  • Jun 01, 2007
  • Y You +2
  • Conference Article
  • Citations486

Hop-count filtering

  • Oct 27, 2003
  • Cheng Jin +2
  • Research Article
  • Citations12

QoS routing in GMPLS-capable integrated IP/WDM networks with router cost constraints

  • Oct 12, 2007
  • Computer Communications
  • G Mohan +1
  • Conference Article
  • Citations4

Improving Quality of Service in MAC 802.11 Layer

  • Oct 01, 2007
  • Proceedings - International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems
  • N Sundareswaran +2
  • Research Article
  • Citations2

Networking with AI: Optimizing Network Planning, Management, and Security through the medium of Artificial Intelligence

  • Jun 24, 2025
  • IARJSET
  • Book Chapter
  • Citations4

T-RAP: (TCP Reply Acknowledgement Packet) a Resilient Filtering Model for DDoS Attack with Spoofed IP Address

  • Jan 01, 2011
  • L Kavisankar +1
  • Conference Article
  • Citations15

A scheme of distributed hop-count filtering of traffic

  • Jan 01, 2009
  • Xia Wang +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.