{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T16:11:06Z","timestamp":1746115866482,"version":"3.40.4"},"publisher-location":"Berlin, Heidelberg","reference-count":33,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642414879"},{"type":"electronic","value":"9783642414886"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-41488-6_20","type":"book-chapter","created":{"date-parts":[[2013,10,1]],"date-time":"2013-10-01T06:05:49Z","timestamp":1380607549000},"page":"297-312","source":"Crossref","is-referenced-by-count":0,"title":["An Adaptive Mitigation Framework for Handling Suspicious Network Flows via MPLS Policies"],"prefix":"10.1007","author":[{"given":"Nabil","family":"Hachem","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joaquin","family":"Garcia-Alfaro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Herv\u00e9","family":"Debar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"20_CR1","unstructured":"Eclipse. The Eclipse Foundation open source community website, http:\/\/www.eclipse.org\/"},{"key":"20_CR2","unstructured":"MotOrBAC: an Open-Source OrBAC Policy Editor, http:\/\/motorbac.sourceforge.net\/"},{"key":"20_CR3","unstructured":"MPLS for Linux, http:\/\/mpls-linux.sourceforge.net\/"},{"key":"20_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1007\/978-3-642-03007-9_4","volume-title":"Data and Applications Security XXIII","author":"F. Autrel","year":"2009","unstructured":"Autrel, F., Cuppens-Boulahia, N., Cuppens, F.: Reaction Policy Model Based on Dynamic Organizations and Threat Context. In: Gudes, E., Vaidya, J. (eds.) Data and Applications Security XXIII. LNCS, vol.\u00a05645, pp. 49\u201364. Springer, Heidelberg (2009)"},{"key":"20_CR5","doi-asserted-by":"crossref","unstructured":"Awduche, D., Malcolm, J., Agogbua, J., O\u2019Dell, M., McManus, J.: Requirements for Traffic Engineering Over MPLS. RFC 2702 (Informational) (September 1999)","DOI":"10.17487\/rfc2702"},{"key":"20_CR6","doi-asserted-by":"crossref","unstructured":"Brunner, M., Quittek, J.: MPLS Management using Policies. In: 2001 IEEE\/IFIP International Symposium on Integrated Network Management Proceedings, pp. 515\u2013528 (2001)","DOI":"10.1109\/INM.2001.918063"},{"key":"20_CR7","doi-asserted-by":"publisher","first-page":"416","DOI":"10.1109\/CSAC.2003.1254346","volume-title":"Proceedings of the 19th Annual Computer Security Applications Conference, ACSAC 2003","author":"F. Cuppens","year":"2003","unstructured":"Cuppens, F., Alexandre, M.: Modelling Contexts in the Or-BAC Model. In: Proceedings of the 19th Annual Computer Security Applications Conference, ACSAC 2003, pp. 416\u2013425. IEEE Computer Society, Washington, DC (2003)"},{"key":"20_CR8","series-title":"IFIP","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/0-387-24098-5_15","volume-title":"Formal Aspects in Security and Trust","author":"F. Cuppens","year":"2005","unstructured":"Cuppens, F., Boulahia-Cuppens, N., Sans, T., Miege, A.: A Formal Approach to Specify and Deploy a Network Security Policy. In: Dimitrakos, T., Martinelli, F. (eds.) Formal Aspects in Security and Trust. IFIP, vol.\u00a0173, pp. 203\u2013218. Springer, Boston (2005)"},{"key":"20_CR9","unstructured":"Cuppens, F., Cuppens-Boulahia, N., Miege, A.: Inheritance Hierarchies in the OrBAC Model and Application in a Network Security Environment. In: Second Foundations of Computer Security Workshop, FCS 2004 (2004)"},{"key":"20_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/3-540-44569-2_2","volume-title":"Policies for Distributed Systems and Networks","author":"N. Damianou","year":"2001","unstructured":"Damianou, N., Dulay, N., Lupu, E.C., Sloman, M.: The Ponder Policy Specification Language. In: Sloman, M., Lobo, J., Lupu, E.C. (eds.) POLICY 2001. LNCS, vol.\u00a01995, pp. 18\u201338. Springer, Heidelberg (2001)"},{"key":"20_CR11","doi-asserted-by":"crossref","unstructured":"Debar, H., Curry, D., Feinstein, B.: The Intrusion Detection Message Exchange Format (IDMEF). RFC 4765 (Experimental) (March 2007)","DOI":"10.17487\/rfc4765"},{"key":"20_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1007\/11790754_7","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"H. Debar","year":"2006","unstructured":"Debar, H., Thomas, Y., Boulahia-Cuppens, N., Cuppens, F.: Using Contextual Security Policies for Threat Response. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 109\u2013128. Springer, Heidelberg (2006)"},{"issue":"4","key":"20_CR13","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/s11416-007-0039-z","volume":"3","author":"H. Debar","year":"2007","unstructured":"Debar, H., Thomas, Y., Cuppens, F., Boulahia-Cuppens, N.: Enabling Automated Threat Response through the Use of a Dynamic Security Policy. Journal in Computer Virology\u00a03(4), 195\u2013210 (2007)","journal-title":"Journal in Computer Virology"},{"key":"20_CR14","doi-asserted-by":"crossref","unstructured":"Le Faucheur, F., Wu, L., Davie, B., Davari, S., Vaananen, P., Krishnan, R., Cheval, P., Heinanen, J.: Multi-Protocol Label Switching (MPLS) Support of Differentiated Services. RFC 3270 (Proposed Standard), Updated by RFC 5462 (May 2002)","DOI":"10.17487\/rfc3270"},{"key":"20_CR15","doi-asserted-by":"publisher","first-page":"532","DOI":"10.1109\/ARES.2007.34","volume-title":"Proceedings of the Second International Conference on Availability, Reliability and Security, ARES 2007","author":"J. Garcia-Alfaro","year":"2007","unstructured":"Garcia-Alfaro, J., Cuppens, F., Cuppens-Boulahia, N.: Aggregating and Deploying Network Access Control Policies. In: Proceedings of the Second International Conference on Availability, Reliability and Security, ARES 2007, pp. 532\u2013542. IEEE Computer Society, Washington, DC (2007)"},{"key":"20_CR16","doi-asserted-by":"crossref","unstructured":"Hachem, N., Debar, H., Garcia-Alfaro, J.: HADEGA: a Novel MPLS-based Mitigation Solution to Handle Network Attacks. In: 2012 IEEE 31st International Performance Computing and Communications Conference (IPCCC), pp. 171\u2013180. IEEE (December 2012)","DOI":"10.1109\/PCCC.2012.6407750"},{"issue":"1","key":"20_CR17","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1016\/j.comnet.2011.09.014","volume":"56","author":"W. Han","year":"2012","unstructured":"Han, W., Lei, C.: Survey Paper: a Survey on Policy Languages in Network and Security Management. Computer Networks\u00a056(1), 477\u2013489 (2012)","journal-title":"Computer Networks"},{"key":"20_CR18","unstructured":"Hassan, A., Hudec, L.: Role Based Network Security Model: A Forward Step towards Firewall Management. In: Workshop on Security of Information Technologies (2003)"},{"key":"20_CR19","unstructured":"Isoyama, K., Brunner, M., Yoshida, M., Quittek, J., Chadha, R., Mykoniatis, G., Poylisher, A., Vaidyanathan, R., Kind, A., Reichmeyer, F.: Policy Framework MPLS Information Model for QoS and TE. IETF Internet Draft \u2013 expired\u00a001 (December 2000)"},{"key":"20_CR20","unstructured":"Kagal, L.: Rei: a Policy Language for the Me-Centric Project. Technical report, HP labs (2002)"},{"key":"20_CR21","unstructured":"Abou El Kalam, A., El Baida, R., Balbiani, P., Benferhat, S., Cuppens, F., Deswarte, Y., Miege, A., Saurel, C., Trouessin, G.: Organization Based Access Control. In: 4th International Workshop on Policies for Distributed Systems and Networks (Policy 2003), pp. 120\u2013131. IEEE (2003)"},{"key":"20_CR22","first-page":"291","volume-title":"Proceedings of the Sixteenth National Conference on Artificial Intelligence and the Eleventh Innovative Applications of Artificial Intelligence Conference Innovative Applications of Artificial Intelligence, AAAI 1999\/IAAI 1999","author":"J. Lobo","year":"1999","unstructured":"Lobo, J., Bhatia, R., Naqvi, S.: A Policy Description Language. In: Proceedings of the Sixteenth National Conference on Artificial Intelligence and the Eleventh Innovative Applications of Artificial Intelligence Conference Innovative Applications of Artificial Intelligence, AAAI 1999\/IAAI 1999, pp. 291\u2013298. American Association for Artificial Intelligence, Menlo Park (1999)"},{"key":"20_CR23","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1109\/POLICY.2002.1011302","volume-title":"Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY 2002)","author":"L. Lymberopoulos","year":"2002","unstructured":"Lymberopoulos, L., Lupu, E., Sloman, M.: An Adaptive Policy based Management Framework for Differentiated Services Networks. In: Proceedings of the 3rd International Workshop on Policies for Distributed Systems and Networks (POLICY 2002), pp. 147\u2013158. IEEE Computer Society, Washington, DC (2002)"},{"issue":"3","key":"20_CR24","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1023\/A:1025719407427","volume":"11","author":"L. Lymberopoulos","year":"2003","unstructured":"Lymberopoulos, L., Lupu, E., Sloman, M.: An Adaptive Policy-based Framework for Network Services Management. J. Netw. Syst. Manage.\u00a011(3), 277\u2013303 (2003)","journal-title":"J. Netw. Syst. Manage."},{"key":"20_CR25","doi-asserted-by":"crossref","unstructured":"Rosen, E., Viswanathan, A., Callon, R.: Multiprotocol Label Switching Architecture. RFC 3031 (Proposed Standard) (January 2001)","DOI":"10.17487\/rfc3031"},{"key":"20_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/3-540-45608-2_3","volume-title":"Foundations of Security Analysis and Design","author":"P. Samarati","year":"2001","unstructured":"Samarati, P., di Vimercati, S.d.C.: Access control: Policies, models, and mechanisms. In: Focardi, R., Gorrieri, R. (eds.) FOSAD 2000. LNCS, vol.\u00a02171, p. 137. Springer, Heidelberg (2001)"},{"issue":"2","key":"20_CR27","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R. Sandhu","year":"1996","unstructured":"Sandhu, R., Coyne, E., Feinstein, H., Youman, C.: Role-Based Access Control Models. Computer\u00a029(2), 38\u201347 (1996)","journal-title":"Computer"},{"key":"20_CR28","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1007\/BF02283186","volume":"2","author":"M. Sloman","year":"1994","unstructured":"Sloman, M.: Policy Driven Management for Distributed Systems. Journal of Network and Systems Management\u00a02, 333\u2013360 (1994)","journal-title":"Journal of Network and Systems Management"},{"key":"20_CR29","doi-asserted-by":"crossref","unstructured":"Snir, Y., Ramberg, Y., Strassner, J., Cohen, R., Moore, B.: Policy Quality of Service (QoS) Information Model. RFC 3644 (Proposed Standard) (November 2003)","DOI":"10.17487\/rfc3644"},{"key":"20_CR30","unstructured":"Sophos: Security Threat Report 2012 (2012)"},{"issue":"1","key":"20_CR31","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1109\/65.898818","volume":"15","author":"G.N. Stone","year":"2001","unstructured":"Stone, G.N., Lundy, B., Xie, G.G.: Network Policy Languages: a Survey and a New Approach. IEEE Network\u00a015(1), 10\u201321 (2001)","journal-title":"IEEE Network"},{"key":"20_CR32","unstructured":"The OASIS technical commitee. XACML: eXtensible Access Control Markup Language (2005)"},{"key":"20_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/3-540-44569-2_9","volume-title":"Policies for Distributed Systems and Networks","author":"D. Verma","year":"2001","unstructured":"Verma, D., Beigi, M., Jennings, R.: Policy Based SLA Management in Enterprise Networks. In: Sloman, M., Lobo, J., Lupu, E.C. (eds.) POLICY 2001. LNCS, vol.\u00a01995, pp. 137\u2013152. Springer, Heidelberg (2001)"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-41488-6_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T15:04:28Z","timestamp":1746025468000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-41488-6_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642414879","9783642414886"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-41488-6_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}