首页> 外文会议>International Conference on Communications >On a Game Theoretic Approach to Detect the Low-Rate Denial of Service Attacks
【24h】

On a Game Theoretic Approach to Detect the Low-Rate Denial of Service Attacks

机译:一种用于检测低速率拒绝服务攻击的博弈论方法

获取原文

摘要

The Low-Rate DoS attacks such as “Shrew” and “New Shrew” attacks, unlike the high rate attacks, are hard for the router to detect. Attackers choose a malicious low-rate bandwidth to exploit the TCP's congestion control window algorithm and the transition time-out mechanism. By using a game theoretic approach, we focus on the best strategy and solution for a computer network to detect the Low-Rate Denial of Service attacks. In our experiments we simulated the network congestion attacks and we proposed a practical solution by using a sigmoid filter. The proposed solution is to create a threshold bandwidth filter at the router that allows a specific bandwidth, so when traffic exceeds the threshold it will be dropped, or if the traffic is below the threshold, it will be redirected to a honeypot server. In our game theory approach, we considered the game players in a static simultaneous game. The defender's strategy is to determine an optimal firewall option to detect the attacker traffic, and the attacker's strategy is to find the low rate to exploit the retransmission time-out mechanism and elude the detector. We calculated the payoff for the each player and for each strategy. We solved the game by finding the Nash Equilibrium where players do not have any profit in using any other strategy. Our experiments and calculations lead to the conclusion that a mixed strategy will the best response for an organization which will be using the proposed approach.
机译:与高速率攻击不同,低速率DoS攻击(例如“ Shrew”和“ New Shrew”攻击)很难被路由器检测到。攻击者选择恶意的低速率带宽来利用TCP的拥塞控制窗口算法和过渡超时机制。通过使用博弈论方法,我们专注于计算机网络检测低速率拒绝服务攻击的最佳策略和解决方案。在我们的实验中,我们模拟了网络拥塞攻击,并提出了使用S型滤波器的实用解决方案。提出的解决方案是在允许特定带宽的路由器上创建阈值带宽过滤器,因此,如果流量超过阈值,流量将被丢弃,或者如果流量低于阈值,则流量将被重定向到蜜罐服务器。在我们的博弈论方法中,我们在静态同时游戏中考虑了游戏玩家。防御者的策略是确定检测攻击者流量的最佳防火墙选项,攻击者的策略是找到低速率以利用重传超时机制并逃避检测器。我们计算了每个参与者和每个策略的收益。我们通过找到纳什均衡来解决游戏,在该纳什均衡中,玩家使用任何其他策略都无法获得任何利润。我们的实验和计算得出的结论是,混合策略将为使用建议方法的组织提供最佳响应。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号