The Experts below are selected from a list of 282 Experts worldwide ranked by ideXlab platform

Quanyan Zhu - One of the best experts on this subject based on the ideXlab platform.

  • GameSec - Proactive Defense Against Physical Denial of Service Attacks Using Poisson Signaling Games
    Lecture Notes in Computer Science, 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, distributed denial-of-service (DDoS) attacks overload the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch “physical” denial-of-service attacks (PDoS) in which IoT devices overflow the “physical bandwidth” of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. In order to model the recruitment of bots, we develop a “Poisson signaling game,” a signaling game with an unknown number of receivers, which have varying abilities to detect deception. Then we use a version of this game to analyze two mechanisms (legal and economic) to deter Botnet recruitment. Equilibrium results indicate that (1) defenders can bound Botnet Activity, and (2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for proactive PDoS defense.

  • Proactive Population-Risk Based Defense Against Denial of Cyber-Physical Service Attacks
    arXiv preprint arXiv:1705.00682, 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, DDoS attacks work by overflowing the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch a "physical" denial-of-service attack (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. To model the recruitment of bots, we extend a traditional game-theoretic concept and create a "Poisson signaling game." Then we analyze two different mechanisms (legal and economic) to deter Botnet recruitment. We find that 1) defenders can bound Botnet Activity and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for designing proactive defense against PDoS attacks.

  • Proactive Defense Against Physical Denial of Service Attacks Using Poisson Signaling Games
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, distributed denial-of-service (DDoS) attacks overload the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch "physical" denial-of-service attacks (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. In order to model the recruitment of bots, we develop a "Poisson signaling game," a signaling game with an unknown number of receivers, which have varying abilities to detect deception. Then we use a version of this game to analyze two mechanisms (legal and economic) to deter Botnet recruitment. Equilibrium results indicate that 1) defenders can bound Botnet Activity, and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for proactive PDoS defense.

Jeffrey Pawlick - One of the best experts on this subject based on the ideXlab platform.

  • GameSec - Proactive Defense Against Physical Denial of Service Attacks Using Poisson Signaling Games
    Lecture Notes in Computer Science, 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, distributed denial-of-service (DDoS) attacks overload the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch “physical” denial-of-service attacks (PDoS) in which IoT devices overflow the “physical bandwidth” of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. In order to model the recruitment of bots, we develop a “Poisson signaling game,” a signaling game with an unknown number of receivers, which have varying abilities to detect deception. Then we use a version of this game to analyze two mechanisms (legal and economic) to deter Botnet recruitment. Equilibrium results indicate that (1) defenders can bound Botnet Activity, and (2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for proactive PDoS defense.

  • Proactive Population-Risk Based Defense Against Denial of Cyber-Physical Service Attacks
    arXiv preprint arXiv:1705.00682, 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, DDoS attacks work by overflowing the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch a "physical" denial-of-service attack (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. To model the recruitment of bots, we extend a traditional game-theoretic concept and create a "Poisson signaling game." Then we analyze two different mechanisms (legal and economic) to deter Botnet recruitment. We find that 1) defenders can bound Botnet Activity and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for designing proactive defense against PDoS attacks.

  • Proactive Defense Against Physical Denial of Service Attacks Using Poisson Signaling Games
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017
    Co-Authors: Jeffrey Pawlick, Quanyan Zhu
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, distributed denial-of-service (DDoS) attacks overload the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch "physical" denial-of-service attacks (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. In order to model the recruitment of bots, we develop a "Poisson signaling game," a signaling game with an unknown number of receivers, which have varying abilities to detect deception. Then we use a version of this game to analyze two mechanisms (legal and economic) to deter Botnet recruitment. Equilibrium results indicate that 1) defenders can bound Botnet Activity, and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for proactive PDoS defense.

Troy Mursch - One of the best experts on this subject based on the ideXlab platform.

  • GLOBECOM - Profiling IoT-Based Botnet Traffic Using DNS
    2019 IEEE Global Communications Conference (GLOBECOM), 2019
    Co-Authors: Owen P. Dwyer, Angelos K. Marnerides, Vasileios Giotsas, Troy Mursch
    Abstract:

    Internet-wide security and resilience have traditionally been subject to large-scale DDoS attacks initiated by various types of Botnets. Since the Mirai outbreak in 2016 myriads of Mirai-alike IoT-based Botnets have emerged. Such Botnets rely on Mirai's base malware code and they infiltrate vulnerable IoT devices on an Internet-wide scale such as to instrument them to perform large-scale attacks such as DDoS. As recently shown, DDoS attacks triggered by Mirai-alike IoT-based Botnets go far beyond traditional pre-2016 DDoS attacks since they have a much higher amplification and their propagation is far more aggressive. Thus, it is of crucial importance to tailor Botnet detection schemes accordingly. This work provides a novel DNS-based profiling scheme over real datasets of Mirai-alike Botnet Activity captured on honeypots that are globally distributed. We firstly discuss features used in profiling Botnets in the past and indicate how profiling IoT-based Botnets in particular can be improved by leveraging DNS information out of a single DNS record. We further conduct an evaluation of our developed feature set over various Machine Learning (ML) classifiers and demonstrate the applicability of our scheme. Our resulted outputs indicate that the proposed feature set can significantly reduce Botnet detection time whilst simultaneously maintaining high levels of accuracy of 99% on average under the random forest formulation.

Owen P. Dwyer - One of the best experts on this subject based on the ideXlab platform.

  • GLOBECOM - Profiling IoT-Based Botnet Traffic Using DNS
    2019 IEEE Global Communications Conference (GLOBECOM), 2019
    Co-Authors: Owen P. Dwyer, Angelos K. Marnerides, Vasileios Giotsas, Troy Mursch
    Abstract:

    Internet-wide security and resilience have traditionally been subject to large-scale DDoS attacks initiated by various types of Botnets. Since the Mirai outbreak in 2016 myriads of Mirai-alike IoT-based Botnets have emerged. Such Botnets rely on Mirai's base malware code and they infiltrate vulnerable IoT devices on an Internet-wide scale such as to instrument them to perform large-scale attacks such as DDoS. As recently shown, DDoS attacks triggered by Mirai-alike IoT-based Botnets go far beyond traditional pre-2016 DDoS attacks since they have a much higher amplification and their propagation is far more aggressive. Thus, it is of crucial importance to tailor Botnet detection schemes accordingly. This work provides a novel DNS-based profiling scheme over real datasets of Mirai-alike Botnet Activity captured on honeypots that are globally distributed. We firstly discuss features used in profiling Botnets in the past and indicate how profiling IoT-based Botnets in particular can be improved by leveraging DNS information out of a single DNS record. We further conduct an evaluation of our developed feature set over various Machine Learning (ML) classifiers and demonstrate the applicability of our scheme. Our resulted outputs indicate that the proposed feature set can significantly reduce Botnet detection time whilst simultaneously maintaining high levels of accuracy of 99% on average under the random forest formulation.

Zhu Quanyan - One of the best experts on this subject based on the ideXlab platform.

  • Proactive Population-Risk Based Defense Against Denial of Cyber-Physical Service Attacks
    2017
    Co-Authors: Pawlick Jeffrey, Zhu Quanyan
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, DDoS attacks work by overflowing the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch a "physical" denial-of-service attack (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. To model the recruitment of bots, we extend a traditional game-theoretic concept and create a "Poisson signaling game." Then we analyze two different mechanisms (legal and economic) to deter Botnet recruitment. We find that 1) defenders can bound Botnet Activity and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for designing proactive defense against PDoS attacks.Comment: This article was not accepted. It has been revised and appears here: arXiv:1707.0370

  • Proactive Defense Against Physical Denial of Service Attacks using Poisson Signaling Games
    2017
    Co-Authors: Pawlick Jeffrey, Zhu Quanyan
    Abstract:

    While the Internet of things (IoT) promises to improve areas such as energy efficiency, health care, and transportation, it is highly vulnerable to cyberattacks. In particular, distributed denial-of-service (DDoS) attacks overload the bandwidth of a server. But many IoT devices form part of cyber-physical systems (CPS). Therefore, they can be used to launch "physical" denial-of-service attacks (PDoS) in which IoT devices overflow the "physical bandwidth" of a CPS. In this paper, we quantify the population-based risk to a group of IoT devices targeted by malware for a PDoS attack. In order to model the recruitment of bots, we develop a "Poisson signaling game," a signaling game with an unknown number of receivers, which have varying abilities to detect deception. Then we use a version of this game to analyze two mechanisms (legal and economic) to deter Botnet recruitment. Equilibrium results indicate that 1) defenders can bound Botnet Activity, and 2) legislating a minimum level of security has only a limited effect, while incentivizing active defense can decrease Botnet Activity arbitrarily. This work provides a quantitative foundation for proactive PDoS defense.Comment: 2017 Conference on Decision and Game Theory for Security (GameSec2017). arXiv admin note: text overlap with arXiv:1703.0523