ISCAS OpenIR
some improvements to the cost-based framework for analyzing denial of service attacks
Yue Qinggang; Liu Feng; Xue Rui
2012
Conference NameTrusted Systems Third International Conference, INTRUST 2011
SourceTrusted Systems
Pages84-101
Conference Date2011
Conference PlaceBeijing China
Indexed TypeSPRINGER ; EI
ISSN0302-9743
ISBN978-3-642-32297-6
DepartmentThe State Key Laboratory of Information Security Institute of Software Chinese Academy of Sciences Beijing 100190 China
English AbstractRecently, people are paying more attention to formalizing and analyzing Denial of Service (DoS) attacks, but the known analysis models are either not precise enough or not readily used in an automatic way. In this paper, we make some improvements to the cost-based framework proposed by Meadows that aims to formalize DoS attacks. After improvement, the framework models intruders and protocols faithfully in CoreASM, and in a more accurate way in specification. Besides, the analysis can be performed automatically. In the improvements, a more flexible tolerance relation is defined so that the analysis result is in a broad form rather than merely binary as in previous works. Also, concrete values are used for representing the operational costs so as to make cost functions more precise and flexible in analysis. In this paper, the JFKi protocol is automatically analyzed as an indication of the advantages of the improvements. It explores the vulnerability that was previously found manually. The discussion on the JFKi protocol shows some difficulties in designing and analyzing DoS-resistent protocols.; Recently, people are paying more attention to formalizing and analyzing Denial of Service (DoS) attacks, but the known analysis models are either not precise enough or not readily used in an automatic way. In this paper, we make some improvements to the cost-based framework proposed by Meadows that aims to formalize DoS attacks. After improvement, the framework models intruders and protocols faithfully in CoreASM, and in a more accurate way in specification. Besides, the analysis can be performed automatically. In the improvements, a more flexible tolerance relation is defined so that the analysis result is in a broad form rather than merely binary as in previous works. Also, concrete values are used for representing the operational costs so as to make cost functions more precise and flexible in analysis. In this paper, the JFKi protocol is automatically analyzed as an indication of the advantages of the improvements. It explores the vulnerability that was previously found manually. The discussion on the JFKi protocol shows some difficulties in designing and analyzing DoS-resistent protocols.
KeywordDenial Of Service &#8211 Formal Modeling &#8211 Cost Based Framework &#8211 Jfki Protocol
SponsorshipBeijing Institute of Technology; ONETS Wireless and Internet Security Company; Singapore Management University; Administrative Committee of Zhongguangcun Haidian Science Park
Language英语
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/15738
Collection中国科学院软件研究所
Recommended Citation
GB/T 7714
Yue Qinggang,Liu Feng,Xue Rui. some improvements to the cost-based framework for analyzing denial of service attacks[C],2012:84-101.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Yue Qinggang]'s Articles
[Liu Feng]'s Articles
[Xue Rui]'s Articles
Baidu academic
Similar articles in Baidu academic
[Yue Qinggang]'s Articles
[Liu Feng]'s Articles
[Xue Rui]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Yue Qinggang]'s Articles
[Liu Feng]'s Articles
[Xue Rui]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.