Network Protection Against Node Attacks Based on Probabilistic Availability Measures

Network Protection Against Node Attacks Based on Probabilistic Availability Measures
复制标题

DOI:
10.1109/tnsm.2021.3067775
复制
发表时间:
2021-09
影响因子:
5.3
通讯作者:
M. Pióro;M. Mycek;A. Tomaszewski
M. Pióro;M. Mycek;A. Tomaszewski
中科院分区:
计算机科学2区
文献类型:
--
作者:
M. Pióro;M. Mycek;A. Tomaszewski

文献摘要

被引文献

相似文献

我们考虑的网络安全和配置管理问题的定位服务控制器,以最大限度地提高服务的可用性,在有针对性的攻击网络基础设施的情况下。假设攻击者有充分的知识的网络拓扑结构,但只能尝试预测控制器的位置,我们模型的攻击者的行为引入一组概率网络可用性措施,并制定一个优化问题模型,确定潜在的最危险的攻击者可能会发起。我们还制定了一个对应的优化模型,允许网络运营商获得最佳的控制器位置,这最大限度地提高了服务的可用性相对于一组给定的网络攻击。我们解释模型,并使用一个运行的小,直观的网络示例来说明我们的考虑。我们还进行了大量的数值实验与现实的网络数据,以评估和比较不同的攻击策略的潜在有效性,以及网络运营商可以采取的对策的有效性。
We consider a network security and configuration management problem of locating service controllers so as to maximize availability of services in case of targeted attacks on the network infrastructure. Assuming that the attacker has full knowledge of the network topology but can only try to predict controller locations, we model the attacker’s behavior introducing a set of probabilistic network availability measures and formulating an optimization problem model that determines the potentially most dangerous attacks the attacker might launch. We also formulate a counter-part optimization model that allows the network operator to derive the optimal placement of controllers, which maximizes availability of services with respect to a given set of network attacks. We explain the models and illustrate our considerations using a running small, intuitive network example. And we also perform extensive numerical experiments with a realistic network data to evaluate and compare the potential effectiveness of different attack strategies, and the effectiveness of the counter-measures that the network operator can adopt.