{"title":"消费者网络中基于区块链的跨域DDoS缓解","authors":"Hajar Moudoud;Zakaria Abou El Houda;Bouziane Brik","doi":"10.1109/TCE.2025.3559451","DOIUrl":null,"url":null,"abstract":"Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms (<inline-formula> <tex-math>$i.e$ </tex-math></inline-formula>., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration <inline-formula> <tex-math>$i.e$ </tex-math></inline-formula>., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility.","PeriodicalId":13208,"journal":{"name":"IEEE Transactions on Consumer Electronics","volume":"71 2","pages":"7095-7104"},"PeriodicalIF":10.9000,"publicationDate":"2025-04-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks\",\"authors\":\"Hajar Moudoud;Zakaria Abou El Houda;Bouziane Brik\",\"doi\":\"10.1109/TCE.2025.3559451\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms (<inline-formula> <tex-math>$i.e$ </tex-math></inline-formula>., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration <inline-formula> <tex-math>$i.e$ </tex-math></inline-formula>., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility.\",\"PeriodicalId\":13208,\"journal\":{\"name\":\"IEEE Transactions on Consumer Electronics\",\"volume\":\"71 2\",\"pages\":\"7095-7104\"},\"PeriodicalIF\":10.9000,\"publicationDate\":\"2025-04-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Transactions on Consumer Electronics\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10960396/\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"ENGINEERING, ELECTRICAL & ELECTRONIC\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Consumer Electronics","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10960396/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
引用次数: 0
摘要
分布式拒绝服务(DDoS)攻击对消费者网络和互联网服务提供商(isp)的可用性和安全性构成重大威胁。这是一个值得关注的问题,因为不安全的物联网(IoT)设备数量的快速增加带来了潜在的漏洞和安全风险。采用域间DDoS协作策略是解决此问题的一个很有前途的解决方案。但是,手动配置和管理跨多个域的资源可能非常耗时、容易出错且效率低下。此外,现有的域间DDoS缓解机制($i。e美元。由于缺乏合作动机,灵活性低,成本高,合作防御机制面临障碍。最重要的是,它们中的许多是集中的,这有单点故障的风险,阻碍了自治系统(as)之间的协作和资源共享。新兴技术,如由网络功能虚拟化(NFV)、软件定义网络(SDN)和区块链支持的数字孪生(DT),为高效灵活的域间DDoS协作提供了新的机会。e美元。,多个基于sdn的域之间的资源共享。在此背景下,我们提出了SecureShare,这是一种新颖的数字双支持域间DDoS缓解框架,允许基于sdn的域之间高效、公平和安全的动态资源共享,通过资源共享来应对大规模DDoS攻击。SecureShare的部署在以太坊的测试网络Sepolia中执行。此外,我们使用Microsoft Azure Digital Twins (ADT)进行了广泛的实验,这是一种用于生成物理对象的孪生图的平台即服务工具。实验结果表明,SecureShare在效率、安全性和灵活性方面都取得了良好的效果。
A Blockchain-Based Cross-Domain DDoS Mitigation in Consumer Networks
Distributed Denial of Service (DDoS) attacks pose significant threats to the availability and security of consumer networks and Internet service providers (ISPs). This is a significant concern due to the potential vulnerabilities and security risks associated with the rapid increase in the number of insecure Internet of Things (IoT) devices. Adopting an inter-domain DDoS collaboration strategy is a promising solution to address this issue. However, manual configuration and management of resources across multiple domains can be time-consuming, error-prone, and inefficient. Moreover, the existing inter-domain DDoS mitigation mechanisms ($i.e$ ., Cooperative Defense mechanisms) are facing obstacles due to the lack of incentives for cooperation, low flexibility, and high cost. Most importantly, many of them are centralized, which risks single points of failure, hampering collaboration and resource sharing among Autonomous Systems (ASs). The new emerging techniques, such as Digital-Twin (DT) empowered by Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Blockchain introduce new opportunities for efficient and flexible inter-domain DDoS collaboration $i.e$ ., resources sharing among multiple SDN-based domains. In this context, we propose SecureShare, a novel digital twin-enabled inter-domain DDoS mitigation framework that allows for an efficient, fair, and secure dynamic resource-sharing among SDN-based domains to deal with large-scale DDoS attacks through resource sharing. The deployment of SecureShare is executed within Ethereum’s test network, Sepolia. Furthermore, we performed extensive experiments employing Microsoft Azure Digital Twins (ADT), a platform-as-a-service tool for generating twin graphs of physical objects. The experimental results show that SecureShare achieves promising results in terms of efficiency, security, and flexibility.
期刊介绍:
The main focus for the IEEE Transactions on Consumer Electronics is the engineering and research aspects of the theory, design, construction, manufacture or end use of mass market electronics, systems, software and services for consumers.