Defending Link Flooding Attacks under Incomplete Information: A Bayesian Game Approach.

Xu Chen,Wei Feng,Ning Ge,Xianbin Wang
DOI: https://doi.org/10.1109/icc40277.2020.9148653
2020-01-01
Abstract:The link flooding attack (LFA) arises as a new class of Distributed Denial of Service (DDoS) attacks in recent years. By aggregating low-rate protocol-conforming traffic to congest selected links, LFAs can degrade the connectivity of target servers indirectly. Due to the fast proliferation of insecure Internet of Things (IoT) devices, the deployment of botnets is getting easier, which dramatically increases the risk of LFAs. Since the attacking traffic may not reach the victims directly and seems to be legitimate, LFAs are extremely difficult to detect and defend using traditional methods. In this work, we model the interaction between the LFA attacker and the defender as an extensive form game with incomplete information. By using action space compression and the divide and conquer method, we analyze the Nash equilibrium of the subgame on each link, which reveals the rational behaviors of attackers and the optimal strategies of defenders. Furthermore, we concretely expound how to adopt local optimal strategies in the Internet-wide scenario. Experimental results show the effectiveness and robustness of our proposed decision-making method in explicit LFA defending scenarios.
What problem does this paper attempt to address?