A Game Theory Based Rate Limiting Scheme Against Distributed Denial-of-Service Attacks

Tian Zhihong,Jiang Wei,Wu Zhen,Zou Xin
DOI: https://doi.org/10.1109/icime.2010.5477866
2010-01-01
Abstract:Distributed Denial-of-Service (DDoS) attacks are a critical threat to the Internet. This paper introduces a novel DDoS defense scheme that supports automated online attack characterizations and accurate attack packet discarding based on game theory. The key idea is to formulate the bandwidth computing as a noncooperative game. And then a high volume of simulations is done to compute the Nash equilibria of the game. DDoS attacks and which kinds of attacking strategies are more dangerous or more likely to be enforced by the attacker are given in the simulations. Our method may substantially improve people's understanding about the nature of the DDoS threat and the defense system's resilience against this threat.
What problem does this paper attempt to address?