DocumentCode :
144194
Title :
Stochastic Game-Based Analysis of the DNS Bandwidth Amplification Attack Using Probabilistic Model Checking
Author :
Deshpande, Tushar ; Katsaros, Panagiotis ; Smolka, Scott A. ; Stoller, Scott D.
Author_Institution :
Dept. of Comput. Sci., Stony Brook Univ., Stony Brook, NY, USA
fYear :
2014
fDate :
13-16 May 2014
Firstpage :
226
Lastpage :
237
Abstract :
The Domain Name System (DNS) is an Internet-wide, hierarchical naming system used to translate domain names into numeric IP addresses. Any disruption of DNS service can have serious consequences. We present a formal game-theoretic analysis of a notable threat to DNS, namely the bandwidth amplification attack (BAA), and the countermeasures designed to defend against it. We model the DNS BAA as a two-player, turn-based, zero-sum stochastic game between an attacker and a defender. The attacker attempts to flood a victim DNS server with malicious traffic by choosing an appropriate number of zombie machines with which to attack. In response, the defender chooses among five BAA countermeasures, each of which seeks to increase the amount of legitimate traffic the victim server processes. To simplify the model and optimize the analysis, our model does not explicitly track the handling of each packet. Instead, our model is based on calculations of the rates at which the relevant kinds of events occur in each state. We use our game-based model of DNS BAA to generate optimal attack strategies, which vary the number of zombies, and optimal defense strategies, which aim to enhance the utility of the BAA countermeasures by combining them in advantageous ways. The goal of these strategies is to optimize the attacker´s and defender´s payoffs, which are defined using probabilistic reward-based properties, and are measured in terms of the attacker´s ability to minimize the volume of legitimate traffic that is processed, and the defender´s ability to maximize the volume of legitimate traffic that is processed.
Keywords :
IP networks; Internet; computer network security; formal verification; game theory; probability; stochastic processes; BAA; DNS bandwidth amplification attack; DNS server; Internet; domain name system; formal game theoretic analysis; hierarchical naming system; malicious traffic; numeric IP addresses; optimal defense strategies; probabilistic model checking; stochastic game based analysis; victim server process; zombie machines; Bandwidth; Computer crime; Games; IP networks; Probabilistic logic; Servers; Stochastic processes; Bandwidth Amplification Attack (BAA); Domain Name System (DNS); probabilistic model checking; stochastic games;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Computing Conference (EDCC), 2014 Tenth European
Conference_Location :
Newcastle
Type :
conf
DOI :
10.1109/EDCC.2014.37
Filename :
6821109
Link To Document :
بازگشت