Back to Search
Start Over
Dynamic game model of botnet DDoS attack and defense
- Source :
- Security and Communication Networks. 9:3127-3140
- Publication Year :
- 2016
- Publisher :
- Wiley, 2016.
-
Abstract
- Botnet has become a popular technique for deploying Internet crimes. The command of botnet has evolved into a major way for attackers to launch Distributed Denial of Service attacks on network servers. Modelized analysis methods need to be studied for botnet attacks implements, defense, and prediction. In this paper, we propose a novel game theory-based model to describe the scenario, in which the botmaster launching Distributed Denial of Service attacks using a botnet while the defender equipped a firewall defending. In our model, we consider the following: firstly, the botmaster and the defender can be rational or irrational; secondly, the interaction between the botmaster and the defender is modeled as a dynamic game; thirdly, their supporting or not self-learning databases. We detail the analysis of eight sub-scenarios for the assumptions and give an easy-to-use algorithm for adjustment of offensive and defensive strategy. We use the OPNET to validate our model and its effectiveness. The experiment result shows that our strategy can improve the firewall abilities to lower false alarm rate FR and improve the botmaster lower exposure rate of botnet to avoid detection. Furthermore, the model is helpful to evaluate defense ability of the defender towards current botmaster attacks by analyzing attack log in sandbox. Copyright © 2016 John Wiley & Sons, Ltd.
- Subjects :
- Computer Networks and Communications
Network security
business.industry
Computer science
Botnet
020206 networking & telecommunications
Denial-of-service attack
02 engineering and technology
Cutwail botnet
Computer security
computer.software_genre
Rustock botnet
Firewall (construction)
Srizbi botnet
0202 electrical engineering, electronic engineering, information engineering
020201 artificial intelligence & image processing
business
Game theory
computer
Information Systems
Subjects
Details
- ISSN :
- 19390114
- Volume :
- 9
- Database :
- OpenAIRE
- Journal :
- Security and Communication Networks
- Accession number :
- edsair.doi...........3e547395d9185e121fe73ac15f00fbfa
- Full Text :
- https://doi.org/10.1002/sec.1518