Computational models for defenses against internet-based attacks
Kathleen M. Carley, Li‐Chiou Chen · 2003
Internet-based attacks have become an important concern to the government and business since more systems are reliant upon the Internet to exchange information. In particular, distributed denial of service (DDOS) attacks have been used as a prevalent way to compromise the availability of networks or information services. The economic incentives of Internet Service Providers (ISPs) to provide DDOS defenses and the public policy concerns to deploy these defenses have not been formally investigated previously. Security services, such as Virtual Private Networks, have been provided by ISPs as optional network services to deal with the secrecy of data transportation. In the case of DDOS attacks, ISPs provide DDOS defenses that ensure the availability of the subscribers' online services. This dissertation proposes that ISPs provide DDOS defenses on their network as security services to their subscribers and studies the service models for providing the defenses and the public policies needed to facilitate the provision of the defenses. The focus will be on the DDOS defenses that actively filter out ongoing attack traffic. This dissertation analyzes how the side effects of defenses influence the provision of the defenses and investigates the economic incentives for the service provision. The contributions of this dissertation are as follows: First, this dissertation categorizes the current defenses that actively respond against DDOS attacks at network routers based on attack detection algorithms and attack responses. Secondly, the service provision model is analyzed based on the performance efficiency of DDOS defenses under various network topologies and various settings in the technology. Next, the economic incentives for ISPs to offer defense services are then analyzed based on empirical data. To operate the DDOS defense services cost effectively, ISPs should set the filter location closer to the attack sources and price subscribers based on their willingness to pay. Finally, cooperation among multiple ISPs on providing the defenses is analyzed. In order to improve the quality of the defenses when attacks are distributed, ISPs should cooperate with other highly influential ISPs. Public policies should encourage source filtering and provide incentives for highly influential ISPs to deploy DDOS defenses.