An Efficient Multiplex Network Model for Effective Honeypot Roaming Against DDoS Attacks

被引:1
作者
Ren, Jianguo [1 ,2 ]
Zhi, Qiang [1 ]
机构
[1] Jiangsu Normal Univ, Coll Comp Sci, Xuzhou 221116, Peoples R China
[2] Jiangsu Normal Univ, Res Ctr Complex Networks & Swarm Intelligence, Xuzhou 221116, Peoples R China
来源
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING | 2024年 / 11卷 / 02期
基金
美国国家科学基金会;
关键词
Denial-of-service attack; Roaming; Servers; Network topology; Optimization; Numerical models; Dynamic scheduling; Honeypot roaming; multiplex network; roaming frequency; network security; SERVICE; INTERNET; PROPAGATION; DYNAMICS; DEFENSE;
D O I
10.1109/TNSE.2023.3333230
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Honeypot roaming represents an effective mechanism against distributed denial of service (DDoS) attacks at the cost of system resources. Currently, the roaming frequency is set randomly, which brings the question of how often honeypots need to roam to minimize the attack impacts while preserving limited system resources. To address this challenge, this paper proposes an effective Multiplex Network Model, called MNM. First, an innovative multiplex network model composed of a normal node layer and a honeypot node layer is constructed, providing a probabilistic description of dynamical functional interaction and achieving the state transition between the two layers. Then, a condition is defined to determine whether nodes can be continuously infected during the DDoS attacks. More importantly, an optimal roaming frequency is theoretically determined using optimization theory to optimize the related parameters. A series of experimental verifications was made in three different two-layer network topologies, and the results indicate that our proposals are effective in reducing attack impacts and lowering resource consumption compared to a series of random roaming frequencies. This study can provide significant guidance for roaming honeypot design.
引用
收藏
页码:1909 / 1921
页数:13
相关论文
共 64 条
  • [61] An SDN-Enabled Proactive Defense Framework for DDoS Mitigation in IoT Networks
    Zhou, Yuyang
    Cheng, Guang
    Yu, Shui
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 5366 - 5380
  • [62] Investigation of epidemic spreading process on multiplex networks by incorporating fatal properties
    Zhu, Peican
    Wang, Xinyu
    Li, Shudong
    Guo, Yangming
    Wang, Zhen
    [J]. APPLIED MATHEMATICS AND COMPUTATION, 2019, 359 : 512 - 524
  • [63] [诸葛建伟 Zhuge Jianwei], 2013, [软件学报, Journal of Software], V24, P825
  • [64] Expert system assessing threat level of attacks on a hybrid SSH honeynet
    Zuzcak, Matej
    Zenka, Milan
    [J]. COMPUTERS & SECURITY, 2020, 92