arrow
Return

Randomized Security Patrolling for Link Flooding Attack Detection

delete2020-07-01
delete22
PRE
AI
X
Xiaobo Ma
B
Bo An
赵梦辰 cover
赵梦辰 (Mengchen Zhao)
X
Xiapu Luo *
薛磊 cover
薛磊 (Lei Xue)
李振华 cover
李振华 (Zhenhua Li)
T
Tony T. N. Miu
X
Xiaohong Guan
DOI:10.1109/TDSC.2019.2892370delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the advancement of large-scale coordinated attacks, the adversary is shifting away from traditional distributed denial of service (DDoS) attacks against servers to sophisticated DDoS attacks against Internet infrastructures. Link flooding attacks (LFAs) are such powerful attacks against Internet links. Employing network measurement techniques, the defender could detect the link under attack. However, given the large number of Internet links, the defender can only monitor a subset of the links simultaneously, whereas any link might be attacked. Therefore, it remains challenging to practically deploy detection methods. This paper addresses this challenge from a game-theoretic perspective, and proposes a randomized approach (like security patrolling) to optimize LFA detection strategies. Specifically, we formulate the LFA detection problem as a Stackelberg security game, and design randomized detection strategies in consideration of the adversary's behavior, where best and quantal response models are leveraged to characterize the adversary's behavior. We employ a series of techniques to solve the nonlinear and nonconvex NP-hard optimization problems for finding the equilibrium. The experimental results demonstrate the necessity of handling LFAs from a game-theoretic perspective and the effectiveness of our solutions. We believe our study is a significant step forward in formally understanding LFA detection strategies.
Keywords:
Servers
Internet
Computer crime
Monitoring
Loss measurement
Degradation
Internet security
link flooding attack
security patrolling
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

H
hong kong polytechnic university
Scholars:
3.0W
Papers: 4.1W
Citations: 921
X
xi'an jiaotong university
Scholars:
9.1W
Papers: 6.6W
Citations: 75
T
tsinghua university
Scholars:
11.7W
Papers: 10.0W
Citations: 137
N
Nanyang Technological University
Scholars:
4.9W
Papers: 4.8W
Citations: 8.1W
researcher View more organizations