Stealthy DGoS Attack: DeGrading of Service Under the Watch of Network Tomography

Stealthy DGoS Attack: DeGrading of Service Under the Watch of Network Tomography
复制标题

DOI:
10.1109/tnet.2021.3058230
复制
发表时间:
2020-07
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Cho-Chun Chiu;T. He
Cho-Chun Chiu;T. He
中科院分区:
其他
文献类型:
--
作者:
Cho-Chun Chiu;T. He

文献摘要

相似文献

网络层析成像是一种监测封闭网络内部无法直接测量的状态的有力工具,在互联网、覆盖网络和全光网络中有着广泛的应用。然而,现有的网络断层扫描解决方案都假设测量值是值得信赖的,这使得它们在具有可能被操纵的测量值的对抗性环境中的有效性成为可能。要了解在这样的设置网络断层扫描的基本限制,我们制定和分析一种新型的攻击,其目的是在最大限度地降低目标路径的性能,而不被本地化的网络断层扫描。通过分析最优攻击策略的性质,我们制定了新的组合优化设计的最优攻击策略,然后将其与著名的NP难问题和近似算法。作为一个副产品,我们的算法还确定近似的最脆弱的一组链接,一旦操纵,可以造成最大的性能下降。我们对真实的拓扑结构的评估表明了这种攻击的巨大潜在危害,表明需要新的防御措施。
Network tomography is a powerful tool to monitor the internal state of a closed network that cannot be measured directly, with broad applications in the Internet, overlay networks, and all-optical networks. However, existing network tomography solutions all assume that the measurements are trust-worthy, leaving open how effective they are in an adversarial environment with possibly manipulated measurements. To understand the fundamental limit of network tomography in such a setting, we formulate and analyze a novel type of attack that aims at maximally degrading the performance of targeted paths without being localized by network tomography. By analyzing properties of the optimal attack strategy, we formulate novel combinatorial optimizations to design the optimal attack strategy, which are then linked to well-known NP-hard problems and approximation algorithms. As a byproduct, our algorithms also identify approximations of the most vulnerable set of links that once manipulated, can inflict the maximum performance degradation. Our evaluations on real topologies demonstrate the large potential damage of such attacks, signaling the need of new defenses.