A NETWORK-LAYER PROTECTION METHODOLOGY FOR MULTISERVICE COMMUNICATION NETWORKS BASED ON OUT-OF-BAND ANOMALY DETECTION
Keywords:
multiservice communication network, network-layer security, anomaly detection, quality of service protection, next generation networks, out-of-band monitoringAbstract
The convergence of voice, video and data services onto a single packet-switched infrastructure has turned the network layer of multiservice communication networks into a single point of failure: a successful attack on Layer 3 degrades every converged service simultaneously. This paper proposes a protection methodology built on the explicit separation of the data plane from the security plane. Transit traffic remains untouched on the hardware forwarding path, while a mirrored copy delivered through a SPAN port is examined by an out-of-band software sensor, so that analysis latency cannot propagate into transit latency by construction. The methodology covers four threat vectors specific to converged environments — source address spoofing, overlapping-fragment attacks, volumetric Layer 3 floods, and manipulation of Differentiated Services markings — the last of which receives comparatively little attention in the literature despite being characteristic of multiservice networks. A prototype sensor was implemented in Go and evaluated on a virtual testbed. Benchmarking places per-packet processing cost between 34.6 ns and 1850 ns depending on detector complexity, three to four orders of magnitude below the end-to-end delay budget for voice traffic defined by ITU-T G.114. Functional testing against a synthetic traffic capture confirmed correct classification of all four attack classes with no false positives on legitimate traffic.
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Progress in Science

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.