SearcharxivSearch

arXiv · 2304.05204

The Time for Reconstructing the Attack Graph in DDoS Attacks

Abstract

Despite their frequency, denial-of-service (DoS\blfootnote{Denial of Service (DoS), Distributed Denial of Service (DDoS), Probabilistic Packet Marking (PPM), coupon collector's problem (CCP)}) and distributed-denial-of-service (DDoS) attacks are difficult to prevent and trace, thus posing a constant threat. One of the main defense techniques is to identify the source of attack by reconstructing the attack graph, and then filter the messages arriving from this source. One of the most common methods for reconstructing the attack graph is Probabilistic Packet Marking (PPM). We focus on edge-sampling, which is the most common method. Here, we study the time, in terms of the number of packets, the victim needs to reconstruct the attack graph when there is a single attacker. This random variable plays an important role in the reconstruction algorithm. Our main result is a determination of the asymptotic distribution and expected value of this time. The process of reconstructing the attack graph is analogous to a version of the well-known coupon collector's problem (with coupons having distinct probabilities). Thus, the results may be used in other applications of this problem.

Explore related subjects

Keep this discovery

BibTeXRIS

Dina Barak-Pelleg, Daniel Berend. 2023-04-11. The Time for Reconstructing the Attack Graph in DDoS Attacks. https://arxiv.org/abs/2304.05204

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Averaging principles for nonautonomous multiscale stochastic Burgers equations with reflection

In this paper, we study averaging principles for nonautonomous multiscale stochastic Burgers equations with reflection. First, we derive a general averaging principle applicable to such equations under minimal assumptions. Subsequently, since the coefficients of the obtained averaged equation still depend on the small scaling parameter $\e$, we impose either periodic or asymptotic conditions on the coefficients, thereby obtain two distinct averaged equations whose coefficients are independent of $\e$ and establish two averaging principles. Stopping times and Khasminskii's time discretization schemes play an important role. Finally, a concrete example is provided to illustrate the applicability and validity of the theoretical results.

math.PR

Spectral properties of Random Matrices

We give the theoretical foundations of random matrix theory through the definitions of a random matrix, a random probability measure and the corresponding empirical spectral distribution. The technical tool we use is the Stieltjes transform method through which we prove optimal convergence of the empirical spectral distribution of random sample covariance matrices to the deterministic Marchenko-Pastur distribution. We also give new results about the rigidity of the eigenvalues of this random sample covariance matrix and the rate of their convergence. We then define the Dyson equation method to prove new local laws about a random matrix model that interpolates between the Marchenko-Pastur distribution, the elliptical law and the circular law. Through our work these local laws can be considered universal.

math.PR

Moments approach for the elephant random walk

We discuss the method of moments for the one-dimensional elephant random walk (ERW). We first derive a differential recurrence relation for the characteristic function of the ERW, which yields a corresponding system of recurrence relations for its moments. We then obtain asymptotic approximations for the moments in each of the three parameter regimes of the ERW. Finally, by establishing the convergence of the moments and verifying the corresponding moment-determinacy conditions, we identify the limiting distributions of the ERW in each regime.

math.PR