TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Mitigating DDoS attacks with an intrusion detection and prevention system based on 2-player Bayesian game theory

* , , , , ,

* Corresponding author · click or hover a name for details

pp. 809–820Vol. 27Issue 2-BMarch 2024DOI: 10.47974/JDMSC-1957 Crossmark XML
Published Online:
12 Apr 2024
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-1957
Pages:
809–820

Abstract

Distributed Denial of Service (DDoS) attacks are very dangerous to the availability and security of networks, so they need improved ways to be stopped. This article suggests a new way to fight DDoS attacks that uses Intrusion Detection and Prevention Systems (IDPS) and 2-Player Bayesian Game Theory. Traditional IDPSs often have trouble responding quickly to changing attack tactics, which makes them less effective as defenses. The suggested structure, on the other hand, imagines the attacker and defense interacting as a Bayesian game. This lets them make proactive choices and come up with flexible ways to respond.The system uses Bayesian reasoning to describe the attacker’s actions and plans’ doubt, which lets it better assess the threat and decide how to respond. By constantly changing probability distributions based on what it sees attackers doing and what it sees defenders doing, the IDPS can quickly and effectively change its defenses to deal with new threats. The strategy contact between the attacker and the defense adds a competition factor that makes attackers less likely to start DDoS attacks by making them more expensive and risky. The proposed method works to stop different kinds of DDoS attacks while reducing the number of fake positives and negatives through a lot of simulations and experiments.

Keywords

Subject Classifications

68M25

References

[1] D. Patel and D. Patel, “PolyDDoSchain - Collaborative Volumetric Distributed Denial of Service Attack Detection and Prevention using Blockchain Technology,” 2023 International Conference on Sustainable Computing and Smart Systems (ICSCSS), Coimbatore, India,  pp. 1571-1578 (2023), doi: 10.1109/ICSCSS57650.2023.10169487. 
[2] S. Vattikuti, M. R. Hegde, M. Manish, V. Bodduvaram and V. Sarasvathi, “DDoS Attack Detection and Mitigation using Anomaly Detection and Machine Learning Models,” 2021 IEEE International Conference on Computation System and Information Technology for Sustainable Solutions (CSITSS), Bangalore, India, 9683214. pp. 1-6 (2021).
[3] J. A. Pérez-Díaz, I. A. Valdovinos, K. -K. R. Choo and D. Zhu, “A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning,” in IEEE Access, vol. 8, pp. 155859-155872 (2020), doi: 10.1109/ACCESS.2020.3019330.
[4] N. Mishra and S. Pandya, “Internet of Things Applications, Security Challenges, Attacks, Intrusion Detection, and Future Visions: A Systematic Review,” in IEEE Access, vol. 9, pp. 59353-59377 (2021), doi: 10.1109/ACCESS.2021.3073408.
[5] N. Kathirkamanathan, B. Thevarasa, G. Mahadevan, N. Skandhakumar and N. Kuruwitaarachchi, “Prevention of DDoS Attacks Targeting Financial Services using Supervised Machine Learning and Stacked LSTM,” 2022 IEEE 7th International conference for Convergence in Technology (I2CT), Mumbai, India, pp. 1-5 (2022), doi: 10.1109/I2CT54291.2022.9825228. 
[6] Ajani, S. N., Khobragade, P., Dhone, M., Ganguly, B., Shelke, N., & Parati, N.  Advancements in Computing: Emerging Trends in Computational Science with Next-Generation Computing. International Journal of Intelligent Systems and Applications in Engineering, 12(7s), 546–559 (2023).
[7] D. Radain, S. Almalki, H. Alsaadi and S. Salama, “A Review on Defense Mechanisms Against Distributed Denial of Service (DDoS) Attacks on Cloud Computing,” 2021 International Conference of Women in Data Science at Taif University (WiDSTaif ), Taif, Saudi Arabia,  pp. 1-6 (2021), doi: 10.1109/WiDSTaif52235.2021.9430220. 
[8] I. Riadi, Sunardi and A. Muhammad, “DDoS Detection Using Artificial Neural Network Regarding Variation of Training Function”, Advanced Science Letters, vol. 24, no. 12, pp. 9163-9167 (2018).
[9] T. Mahjabin, Y. Xiao, G. Sun and W. Jiang, “A survey of distributed denial-of-service attack prevention and mitigation techniques”, International Journal of Distributed Sensor Networks, vol. 13, no. 12, pp. 155014771774146 (2017).
[10] Limkar, Suresh, Ashok, Wankhede Vishal, Singh, Sanjeev, Singh, Amrik, Wagh, Sharmila K. & Ajani, Samir N. A mechanism to ensure identity-based anonymity and authentication for IoT infrastructure using cryptography, Journal of Discrete Mathematical Sciences and Cryptography, 26:5, 1597–1611 (2023).
[11] B. Susilo and R. Sari, “Intrusion Detection in IoT Networks Using Deep Learning Algorithm”, Information, vol. 11, no. 5, pp. 279 (2020).
[12] B. Shah and B. H Trivedi, “Artificial Neural Network based Intrusion Detection System: A Survey”, International Journal of Computer Applications, vol. 39, no. 6, pp. 13-18.

Views: 227Downloads: 5Citations: 0