ITR: Modeling Distributed Denial of Service Attacks and Defenses

ITR:分布式拒绝服务攻击和防御建模

基本信息

  • 批准号:
    0218466
  • 负责人:
  • 金额:
    $ 22.3万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2002
  • 资助国家:
    美国
  • 起止时间:
    2002-10-01 至 2007-09-30
  • 项目状态:
    已结题

项目摘要

Distributed denial of service (DDOS) attacks have emerged as a prevalent way to take down web sites and have imposed financial losses to companies. The CSI/FBI survey (CSI 2001) shows that 36% of respondents in the last 12-months period have detected denial of service, which imposed more than $4.2 million financial losses. The effectiveness of DDOS defenses depends on many factors such that the nature of the network's topology, the specific attack scenario, and various characteristics of the network routers. However, little research has focused on the tradeoffs inherent in this complex system. The researchers are developing a computational testbed to study security policies and the associated technologies that provide defenses against DDOS attacks. The researchers are using this framework to evaluate various policies and technologies. Out model and the ensuing analyses are informed by research in the areas of computer science, information science, organizational theory and social networks.There have been a number of proposals on how to control the on-going DDOS attack traffic. None have been widely deployed. The effectiveness of DDOS defenses depends on many factors, such as the type of network topology, the type of attacks and whether all ISPs are compliant in establishing defenses. However, little is known about the interactions among these factors. Knowing what tradeoffs will occur as these factors vary will enable stakeholders to make more informed security policy decisions in which they adjust for the chance that others may not make the same decisions. Our research illuminates these tradeoffs. Moreover, the computational model the researchers are building enables the user to examine the tradeoffs associated with various DDOS defenses and attack scenarios at the router level.The researchers focus on two basic research questions. First, how do ISPs provide DDOS defenses at the lowest cost while their subscribers remain satisfied with the availability of network connections during attacks? A cost-performance analysis of the effectiveness of DDOS defenses is being conducted using results from the computational model. This cost-performance analysis will aid ISPs and local network administrators in their evaluation of DDOS defenses. Second, the researchers ask where are the critical points in a network to deploy defenses? The researchers examine the impact of network topology on the deployment location of defenses. Graph level indices and models from social network studies will be used to categorize network topologies and to select deployment locations for defenses. This analysis will provide guidance to decision makers.Benefits of this work research include: The policy framework the researchers are developing will help ISPs and subscribers to consider the benefits of providing DDOS defenses and to realize the tradeoffs in DDOS defenses. Results from this study will enable decision makers to make more informed security policy decisions for computer networks. It is costly and unethical to conduct real world experiments of DDOS attacks on large networks. This research will provide a cost effective and ethical means for evaluating various attack scenarios and defenses. Further, topological measures developed in this research should be useful for studies of other large-scale topologies. As such, this work extends social network measures typically used on small person-to-person networks to large-scale computer networks. Finally, this research provides a theoretical basis for evaluating DDOS defenses building on interdisciplinary studies from the fields of computer science, information science, organizational theory and social network analysis.
分布式拒绝服务(DDOS)攻击已经成为一种流行的方式来关闭网站,并给公司带来经济损失。CSI/FBI调查(CSI 2001)显示,在过去12个月内,36%的受访者发现了拒绝服务,造成了420多万美元的经济损失。DDOS防御的有效性取决于许多因素,例如网络拓扑的性质,特定的攻击场景以及网络路由器的各种特性。然而,很少有研究集中在这个复杂的系统中固有的权衡。研究人员正在开发一个计算测试平台,以研究安全策略和相关技术,为DDOS攻击提供防御。 研究人员正在使用这个框架来评估各种政策和技术。我们的模型和随后的分析受到计算机科学、信息科学、组织理论和社交网络领域研究的影响。关于如何控制正在进行的DDOS攻击流量,已经提出了许多建议。没有一个被广泛部署。DDOS防御的有效性取决于许多因素,例如网络拓扑的类型,攻击的类型以及是否所有ISP都符合建立防御的要求。然而,人们对这些因素之间的相互作用知之甚少。了解随着这些因素的变化会发生什么样的权衡,将使利益相关者能够做出更明智的安全策略决策,在这些决策中,他们会根据其他人可能不会做出相同决策的机会进行调整。我们的研究阐明了这些权衡。此外,研究人员正在构建的计算模型使用户能够在路由器级别检查与各种DDOS防御和攻击场景相关的权衡。研究人员专注于两个基本研究问题。首先,ISP如何以最低的成本提供DDOS防御,而他们的用户在攻击期间仍然对网络连接的可用性感到满意?DDOS防御的有效性的成本性能分析正在进行使用计算模型的结果。这种成本性能分析将帮助ISP和本地网络管理员评估DDOS防御。其次,研究人员问,网络中部署防御的关键点在哪里? 研究人员研究了网络拓扑对防御部署位置的影响。社交网络研究的图级索引和模型将用于对网络拓扑进行分类,并选择防御部署位置。这项研究的好处包括:研究人员正在开发的政策框架将帮助ISP和用户考虑提供DDOS防御的好处,并实现DDOS防御的权衡。这项研究的结果将使决策者能够为计算机网络做出更明智的安全策略决策。在大型网络上进行DDOS攻击的真实的世界实验是昂贵且不道德的。这项研究将为评估各种攻击场景和防御提供一种具有成本效益和道德的方法。此外,在这项研究中开发的拓扑措施应该是有用的其他大规模拓扑结构的研究。因此,这项工作将通常用于小型人际网络的社交网络措施扩展到大型计算机网络。最后,本研究从计算机科学、信息科学、组织理论和社会网络分析等多个领域,为评估DDOS防御提供了理论基础。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Kathleen Carley其他文献

A survey of social cybersecurity: Techniques for attack detection, evaluations, challenges, and future prospects
社会网络安全综述:攻击检测技术、评估、挑战及未来展望
  • DOI:
    10.1016/j.chbr.2025.100668
  • 发表时间:
    2025-05-01
  • 期刊:
  • 影响因子:
    5.800
  • 作者:
    Aos Mulahuwaish;Basheer Qolomany;Kevin Gyorick;Jacques Bou Abdo;Mohammed Aledhari;Junaid Qadir;Kathleen Carley;Ala Al-Fuqaha
  • 通讯作者:
    Ala Al-Fuqaha
30. Examining and Characterizing Adolescent-Adult Social Networks, Attitudes Towards Violence and Retaliation, and Violence Exposure
  • DOI:
    10.1016/j.jadohealth.2022.01.143
  • 发表时间:
    2022-04-01
  • 期刊:
  • 影响因子:
  • 作者:
    Alexander T. Riley;Gabrielle Corona;Elizabeth Miller;Kathleen Carley;Alison J. Culyba
  • 通讯作者:
    Alison J. Culyba
28. Adolescent-Adult Support Networks and Violence Exposure Among Male Youth in Low Resource Neighborhoods
  • DOI:
    10.1016/j.jadohealth.2019.11.031
  • 发表时间:
    2020-02-01
  • 期刊:
  • 影响因子:
  • 作者:
    Gabrielle Corona;Nicolás Matheo Kass;Elizabeth Miller;Kathleen Carley;Alison Culyba
  • 通讯作者:
    Alison Culyba

Kathleen Carley的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Kathleen Carley', 18)}}的其他基金

Advancing the Science of Social Cyber-Security Around Information Diffusion and Authenticity
围绕信息传播和真实性推进社会网络安全科学
  • 批准号:
    1849658
  • 财政年份:
    2018
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Collaborative Research: Modeling the Social Actor
合作研究:社会行动者建模
  • 批准号:
    0452598
  • 财政年份:
    2005
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Collaborative Research: Modeling the Social Actor
合作研究:社会行动者建模
  • 批准号:
    0452487
  • 财政年份:
    2005
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Collaborative Research: Dynamics for Social Networks Processes: Comparing Statistical Models with Intelligent Agents
协作研究:社交网络过程的动力学:统计模型与智能代理的比较
  • 批准号:
    0437239
  • 财政年份:
    2004
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Doctoral Dissertation Research: Talking the Talk -- Isomorphism in Organizational Discourse
博士论文研究:说着说着——组织话语中的同构
  • 批准号:
    0201707
  • 财政年份:
    2002
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Doctoral Dissertation Research: Spatial Models of Large-Scale Interpersonal Networks
博士论文研究:大规模人际网络的空间模型
  • 批准号:
    0100999
  • 财政年份:
    2001
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
IGERT Formal Proposal: Multidisciplinary Training Program in Computational Analysis of Social and Organizational Systems
IGERT 正式提案:社会和组织系统计算分析多学科培训计划
  • 批准号:
    9972762
  • 财政年份:
    1999
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Continuing Grant
The Dynamics of Cyberspace: Examining and Modeling Electronic Group Development
网络空间的动态:电子组开发的检查和建模
  • 批准号:
    9711548
  • 财政年份:
    1998
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Organizational Adaptation: The Use of Simulated Annealing to Study Organizational Adaptation
组织适应:利用模拟退火研究组织适应
  • 批准号:
    9633662
  • 财政年份:
    1996
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Continuing Grant
Doctoral Dissertation Research: The Self-Structuring of Support: An Examination of Support Networks under Stress
博士论文研究:支持的自我构建:压力下支持网络的检验
  • 批准号:
    9612326
  • 财政年份:
    1996
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant

相似国自然基金

Galaxy Analytical Modeling Evolution (GAME) and cosmological hydrodynamic simulations.
  • 批准号:
  • 批准年份:
    2025
  • 资助金额:
    10.0 万元
  • 项目类别:
    省市级项目

相似海外基金

ERI: Intelligent Modeling and Parameter Selection in Distributed Optimization for Power Networks
ERI:电力网络分布式优化中的智能建模和参数选择
  • 批准号:
    2347120
  • 财政年份:
    2024
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Forecasting and Modeling of Distributed Energy Resources, and Models for Distributed System Operator Planning and Operation
分布式能源预测和建模以及分布式系统运营商规划和运营模型
  • 批准号:
    572272-2022
  • 财政年份:
    2022
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Alliance Grants
Distributed Converter Modules: Design, Configurations, Aggregated Modeling, and Control
分布式转换器模块:设计、配置、聚合建模和控制
  • 批准号:
    RGPIN-2020-06551
  • 财政年份:
    2022
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Discovery Grants Program - Individual
Collaborative Research: Modeling and Control of Non-Passive Networks with Distributed Time-Delays: Application in Epidemic Control
合作研究:分布式时滞非无源网络的建模与控制:在流行病控制中的应用
  • 批准号:
    2208189
  • 财政年份:
    2022
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Collaborative Research: Modeling and Control of Non-Passive Networks with Distributed Time-Delays: Application in Epidemic Control
合作研究:分布式时滞非无源网络的建模与控制:在流行病控制中的应用
  • 批准号:
    2208182
  • 财政年份:
    2022
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Distributed Converter Modules: Design, Configurations, Aggregated Modeling, and Control
分布式转换器模块:设计、配置、聚合建模和控制
  • 批准号:
    RGPIN-2020-06551
  • 财政年份:
    2021
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Discovery Grants Program - Individual
Excellence in Research: Actor-Based Modeling and Control of Distributed Networked Autonomous Systems with Fault-Tolerant Protocol Settings
卓越研究:具有容错协议设置的分布式网络自治系统的基于参与者的建模和控制
  • 批准号:
    2053412
  • 财政年份:
    2021
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
SitS NSF-UKRI: Collaborative Research: Dynamic Coupling of Soil Structure and Gas Fluxes Measured with Distributed Sensor Systems: Implications for Carbon Modeling
SitS NSF-UKRI:合作研究:用分布式传感器系统测量的土壤结构和气体通量的动态耦合:对碳建模的影响
  • 批准号:
    1935551
  • 财政年份:
    2020
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Standard Grant
Distributed Converter Modules: Design, Configurations, Aggregated Modeling, and Control
分布式转换器模块:设计、配置、聚合建模和控制
  • 批准号:
    RGPIN-2020-06551
  • 财政年份:
    2020
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Discovery Grants Program - Individual
Dynamic coupling of soil structure and gas fluxes measured with distributed sensor systems: implications for carbon modeling
土壤结构与分布式传感器系统测量的气体通量的动态耦合:对碳建模的影响
  • 批准号:
    NE/T010487/1
  • 财政年份:
    2020
  • 资助金额:
    $ 22.3万
  • 项目类别:
    Research Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了