Optimized Cross-Path Attacks via Adversarial Reconnaissance

Optimized Cross-Path Attacks via Adversarial Reconnaissance
复制标题

DOI:
10.1145/3626789
复制
发表时间:
2023-12
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
通讯作者:
Yudi Huang;Yilei Lin;Ting He
Yudi Huang;Yilei Lin;Ting He
中科院分区:
其他
文献类型:
--
作者:
Yudi Huang;Yilei Lin;Ting He

文献摘要

相似文献

虽然软件化和虚拟化技术使现代通信网络看起来更容易管理,但它们也在网络中引入了高度复杂的交互,可能导致意外的安全威胁。在这项工作中,我们研究了一个特定的安全威胁,由于高安全性路径和低安全性路径之间的链接共享,这使得一种新型的拒绝服务攻击,称为交叉路径攻击,间接攻击一组有针对性的高安全性路径(目标路径)通过拥塞的共享链接通过一组攻击者控制的低安全性路径(攻击路径)。虽然这种攻击的可行性最近已经在SDN环境中得到了证明,但其潜在的性能影响尚未得到表征。为此,我们开发了一种方法来设计一个优化的交叉路径攻击下的总攻击率的约束,包括(i)新的侦察算法,可以提供一致的估计的位置和参数的共享链路通过网络断层扫描,和(ii)有效的优化方法来设计的攻击率的最佳分配的攻击路径,以最大限度地降低目标路径的性能。在基于多个网络设置的广泛评估中,所提出的攻击比未优化的攻击对性能的影响要大得多,这表明了在网络设计中解决此类智能攻击的重要性。
While softwarization and virtualization technologies make modern communication networks appear easier to manage, they also introduce highly complex interactions within the networks that can cause unexpected security threats. In this work, we study a particular security threat due to the sharing of links between high-security paths and low-security paths, which enables a new type of DoS attacks, called cross-path attacks, that indirectly attack a set of targeted high-security paths (target paths) by congesting the shared links through a set of attacker-controlled low-security paths (attack paths). While the feasibility of such attacks has been recently demonstrated in the context of SDN, their potential performance impact has not been characterized. To this end, we develop an approach for designing an optimized cross-path attack under a constrained total attack rate, consisting of (i) novel reconnaissance algorithms that can provide consistent estimates of the locations and parameters of the shared links via network tomography, and (ii) efficient optimization methods to design the optimal allocation of attack rate over the attack paths to maximally degrade the performance of the target paths. The proposed attack has achieved a significantly larger performance impact than its non-optimized counterparts in extensive evaluations based on multiple network settings, signaling the importance of addressing such intelligent attacks in network design.