Exploiting the Transients of Adaptation for RoQ Attacks on Internet Resources

  • Authors:
  • Mina Guirguis;Azer Bestavros;Ibrahim Matta

  • Affiliations:
  • Boston University;Boston University;Boston University

  • Venue:
  • ICNP '04 Proceedings of the 12th IEEE International Conference on Network Protocols
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

We expose an unorthodox adversarial attack that exploits the transients of a system's adaptive behavior, as opposed to its limited steady-state capacity. We show that a well orchestrated attack could introduce significant inefficiencies that could potentially deprive a network element from much of its capacity, or significantly reduce its service quality, while evading detection by consuming an unsuspicious, small fraction of that element's hijacked capacity. This type of attack stands in sharp contrast to traditional brute-force, sustained high-rate DoS attacks, as well as recently proposed attacks that exploit specific protocol settings such as TCP timeouts. We exemplify what we term as Reduction of Quality (RoQ) attacks by exposing the vulnerabilities of common adaptation mechanisms. We develop control-theoretic models and associated metrics to quantify these vulnerabilities. We present numerical and simulation results, which we validate with observations from real Internet experiments. Our findings motivate the need for the development of adaptation mechanisms that are resilient to these new forms of attacks.