DocumentCode :
1968142
Title :
Timed CP-Nets Based RoQ Attack Modeling and System Defense Analysis
Author :
He, Yanxiang ; Liu, Tao ; Zhong, Hai ; Liu, Jianbo ; Xiong, Qi
Author_Institution :
State Key Lab. of Software Eng., Wuhan Univ., Wuhan, China
fYear :
2010
fDate :
30-31 Jan. 2010
Firstpage :
199
Lastpage :
204
Abstract :
Current computing systems often employ sophisticated adaptation mechanisms that enable them to deal with overload conditions. Reduction of Quality (RoQ) attack, a novel category of attack being proposed recently, which exploits the adaptive behavior exhibited by various adaptation mechanisms, can cause different forms of damages to the victim system. For the widely used of adaptation mechanisms, RoQ attack can be a critical threat to the Internet. To better analyze the characteristics of RoQ attack and find efficient defense method, an attack modeling and system defense analysis method based on Timed Colored Petri nets (TCPN) is proposed in this paper. Most traditional network attack simulation methods although can simulate the network behavior realistically, they are not capable of simulate the complicated behavior of victim systems, hence can not be used to support the victim-side defense design efficiently. Based on the strong capacity in expression of colored petri nets, our method is more suitable for modeling dynamic behavior of complex system. With this approach, TCPN is used to describe the behavior of network normal traffic, RoQ attacker and victim system. According to the simulation analysis, we also propose an automated on-line defense scheme based on Adaptative Resource Investment. Simulation experiments show that this scheme can reduce the impact of RoQ attack on targeted system efficiently.
Keywords :
Petri nets; computer network security; RoQ attack modeling; adaptative resource investment; adaptive behavior; automated on-line defense scheme; dynamic behavior; reduction of quality attack; system defense analysis; timed colored Petri nets; victim system; victim-side defense design; Aerospace engineering; Helium; Information analysis; Information security; Information technology; Internet; Laboratories; Oceans; Software engineering; Underwater communication; RoQ attack; Simulations; System modeling design; automated on-line defense; timed CPN;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovative Computing & Communication, 2010 Intl Conf on and Information Technology & Ocean Engineering, 2010 Asia-Pacific Conf on (CICC-ITOE)
Conference_Location :
Macao
Print_ISBN :
978-1-4244-5634-5
Electronic_ISBN :
978-1-4244-5635-2
Type :
conf
DOI :
10.1109/CICC-ITOE.2010.58
Filename :
5439257
Link To Document :
بازگشت