Fundamental Limits of Volume-based Network DoS Attacks

Fundamental Limits of Volume-based Network DoS Attacks
复制标题

基于流量的网络 DoS 攻击的基本限制

DOI:
10.1145/3366698
复制
发表时间:
2019
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
通讯作者:
Modiano, Eytan
Modiano, Eytan
中科院分区:
--
文献类型:
--
作者:
Fu, Xinzhe;Modiano, Eytan

文献摘要

参考文献

被引文献

相似文献

基于卷的网络拒绝服务(DoS)攻击是指一类网络攻击,其中对手试图通过发送减少可用用户容量的敌对流量来阻止用户流量。在本文中,我们通过研究对抗性流量的最小所需速率和调查最佳攻击策略来探索基于容量的网络DoS攻击的基本限制。我们从单跳网络开始分析,在单跳网络中,用户流量遵循加入最短队列(JSQ)规则路由到服务器。给定服务器的服务率和用户流量的到达率,我们首先描述了攻击的可行性区域,并证明了攻击是可行的,当且仅当敌对流量的速率位于该区域。然后,我们设计了一种攻击策略,该策略是(i).最优的:它保证攻击的成功,只要敌对流量率位于可行性区域和(ii).不经意的:它不依赖于服务速率或用户流量率的知识。最后,我们扩展我们的结果的可行性区域的攻击和最佳的攻击策略,采用背压(最大权重)路由的多跳网络。在更高的层次上,本文讨论了一类随机网络稳定性的对偶问题,即,如何最佳地去稳定网络。
Volume-based network denial-of-service (DoS) attacks refer to a class of cyber attacks where an adversary seeks to block user traffic from service by sending adversarial traffic that reduces the available user capacity. In this paper, we explore the fundamental limits of volume-based network DoS attacks by studying the minimum required rate of adversarial traffic and investigating optimal attack strategies. We start our analysis with single-hop networks where user traffic is routed to servers following the Join-the-Shortest-Queue (JSQ) rule. Given the service rates of servers and arrival rates of user traffic, we first characterize the feasibility region of the attack and show that the attack is feasible if and only if the rate of the adversarial traffic lies in the region. We then design an attack strategy that is (i).optimal: it guarantees the success of the attack whenever the adversarial traffic rate lies in the feasibility region and (ii).oblivious: it does not rely on knowledge of service rates or user traffic rates. Finally, we extend our results on the feasibility region of the attack and the optimal attack strategy to multi-hop networks that employ Back-pressure (Max-Weight) routing. At a higher level, this paper addresses a class of dual problems of stochastic network stability, i.e., how to optimally de-stabilize a network.
数据包路由对抗排队模型中网络和协议的稳定性
DOI: --
发表时间: 2001
期刊: ACM-SIAM Symposium on Discrete Algorithms
影响因子: --
作者:
Ashish Goel
通讯作者: Ashish Goel
通过立即调度最大限度地减少总流程时间和总完成时间
DOI: --
发表时间: 2003
期刊: ACM Symposium on Parallelism in Algorithms and Architectures
影响因子: --
作者:
N. Avrahami;Y. Azar
通讯作者: Y. Azar
DOI: 10.1016/j.peva.2011.07.015
发表时间: 2011-11-01
影响因子: 2.2
作者:
Lu, Yi;Xie, Qiaomin;Greenberg, Albert
通讯作者: Greenberg, Albert
传感器网络中的最佳过载响应
DOI: --
发表时间: 2006
影响因子: 2.5
作者:
L. Georgiadis;L. Tassiulas
通讯作者: L. Tassiulas
具有最大权重策略的交换网络:流体近似和乘法状态空间崩溃
DOI: 10.1214/11-aap759
发表时间: 2010
期刊: ArXiv
影响因子: --
作者:
Devavrat Shah;D. Wischik
通讯作者: D. Wischik