ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology Inference

ProTO: Proactive Topology Obfuscation Against Adversarial Network Topology Inference
复制标题

DOI:
10.1109/infocom41043.2020.9155255
复制
发表时间:
2020-07
期刊:
IEEE INFOCOM 2020 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
Tao Hou;Zhe Qu;Tao Wang;Zhuo Lu;Yao Liu
Tao Hou;Zhe Qu;Tao Wang;Zhuo Lu;Yao Liu
中科院分区:
其他
文献类型:
--
作者:
Tao Hou;Zhe Qu;Tao Wang;Zhuo Lu;Yao Liu

文献摘要

被引文献

相似文献

网络拓扑是构建网络基础设施功能的基础。在许多情况下,企业网络可能不希望公开其拓扑信息。在本文中,我们的目标是防止攻击,使用对抗性的,积极的端到端拓扑推理,以获得目标网络的拓扑信息。为此,我们提出了一个主动拓扑混淆(ProTO)系统,该系统采用检测然后混淆框架:(i)基于机器学习的轻量级探测行为识别机制被设计用于检测任何探测行为,然后(ii)开发了拓扑混淆设计,以主动延迟所有已识别的探测数据包,使得攻击者将获得结构上准确但虚假的网络拓扑基于这些延迟的探测包的测量,从而欺骗攻击者并降低其对未来推断的亲和力。我们表明,ProTO是非常有效的对主动拓扑推理与最小的性能中断。不同评估场景下的实验结果表明,ProTO能够(i)实现99.9%的检测率,虚警率为3%,(ii)有效地破坏对抗性拓扑推断,并导致攻击者推断的拓扑接近虚假拓扑,(iii)导致整体网络延迟性能下降1.3% -2.0%。
The topology of a network is fundamental for building network infrastructure functionalities. In many scenarios, enterprise networks may have no desire to disclose their topology information. In this paper, we aim at preventing attacks that use adversarial, active end-to-end topology inference to obtain the topology information of a target network. To this end, we propose a Proactive Topology Obfuscation (ProTO) system that adopts a detect-then-obfuscate framework: (i) a lightweight probing behavior identification mechanism based on machine learning is designed to detect any probing behavior, and then (ii) a topology obfuscation design is developed to proactively delay all identified probe packets in a way such that the attacker will obtain a structurally accurate yet fake network topology based on the measurements of these delayed probe packets, therefore deceiving the attacker and decreasing its appetency for future inference. We show that ProTO is very effective against active topology inference with minimum performance disruption. Experimental results under different evaluation scenarios show that ProTO is able to (i) achieve a detection rate of 99.9% with a false alarm of 3%, (ii) effectively disrupt adversarial topology inference and lead to the topology inferred by the attacker close to a fake topology, and (iii) result in an overall network delay performance degradation of 1.3% - 2.0%.