In this paper we present a classification of fuzzy logic systems. We show how the fuzzy logic systems can be divided into different categories depending on their capabilities in handling uncertainties in input data and in rule base representations. We also summarize the strength and weakness of different types of fuzzy logic systems.
This paper presents an expert system (ES) to solve realtime fault identification, isolation and restoration of supply problems in low-voltage distribution networks. The ES receives real-time network status from a Supervisory Control and Data Acquisition (SCADA) system, which monitors the distribution network. The ES's basic architecture, its design and modelling as well as its integration with real-time communication to interface with the SCADA are discussed. The system has been tested with a practical network and the results of the test are presented.
Random early detection (RED) is widely deployed as a congestion control mechanism in the routers. However, RED is often limited by the difficulty of tuning its parameters under different congestion levels. Adaptive RED (ARED) addresses this problem by adaptively adjusting the aggressiveness of RED settings to keep the average queue size between minimum threshold (minth) and maximum threshold (maxth ). We have observed that the additive increase multiplicative decrease (AIMD) approach used in ARED can always maintain high link utilization but not effective enough in preventing high packet loss rates under heavy congestion. In this paper, we propose an adaptive version of RED which applies non-linear power function instead of linear AIMD approach to achieve better link utilization as well as minimizing the packet loss rates under various traffic load conditions
As the use of Internet become increasingly popular, diverse range of network applications which perform different functions are needed to serve user's requirements. However, network system developers face problem to incorporate these new services in their products since the conventional network equipment architectures are monolithic, inflexible, costly and induce long development time. Thus, many developers begin to build their products based on network processor technology that promises more flexibility and therefore, an extensible system. In this paper, we study on the issues and considerations that involved in performing extension on network processor based system. In particular, we address this issue by adding a new building block into the existing router design using Intel IXP2400 network processor.
With the growing use of broadband Internet, the demand for hardware-based intrusion detection system (IDS) is exploding. Network processor is poised to be the future platform for hardware-based IDS and firewall due to its programmability and capability to process packets at wire speed. In this paper, we explore the practical implementation of statistical-based SYN-flooding detection system in a network processor-based router. An embedded architecture, called synmon is proposed. We employ an instance of change-point detection, non-parametric Cumulative Sum (CUSUM) algorithm, for SYNflooding detection. It performs per-flow attack detection based on SYN and ACK packets exchanged in TCP friendly flow. A prototype of synmon embedded forwarder is developed and the performance of synmon under different attack patterns, network loads, sampling interval and tuning parameters is investigated. We demonstrate that the synmon architecture seamlessly integrates with common forwarding tasks while providing cost-effective service for SYN-flooding detection on network processor platform.
Market is an efficient adaptation tool that has been used since the beginning of humans' history to satisfy their everchanging demands and supplies. In doing so, humans are able to adapt to whatever changes, and sustain their survivability. Realizing this fact, we argue that using market-based mechanism may make our computer security system better. Being one of the protection tools, intrusion detection system (IDS) may take the advantages of market-based mechanism to ensure that it always operates with minimum resources to achieve its purpose of detecting intruders and not interrupt users' important tasks. This IDS adapt to the network conditions to sustain its survivability.
Distributed denial-of-service attacks remains inflict damage to the Internet services, after almost five years since its large-scale explosion. The demand for robust and high-speed firewall has led to the advent of hardware-based DDoS defense system. Network processor is becoming the cornerstone of many new firewall designs due to its programmability and high performance packet processing ability. In this paper, we propose an innovative and practical syn-flooding defense system built on network processor. An embedded architecture, called synmon is proposed. We characterize our solution as a source-based autonomous system which resides in upstream border routers. It detects wide-range of attacks and blocks large portion of attack traffic before flooding into core network. Change-point detection algorithm is employed to detect occurrence of syn-flooding attack. It performs per-flow attack detection based on SYN and ACK packets exchanged in TCP friendly flow. A fuzzy-based adaptive rate-limiting mechanism is proposed to restrict intensity of outgoing SYN packets. Under the per-flow mitigation scheme, while the attacker is penalized with limited outgoing connection, the legitimate clients in the same subnet are free from collateral damage. A hardware prototype of synmon embedded router is developed. We demonstrate that the synmon architecture seamlessly integrates with common routing tasks while providing cost-effective service for SYN-flooding defense system on network processor platform.
David Chieng合作论文数School of Electrical and Electronic Engineering, Queen's University of Belfast2