{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T05:23:39Z","timestamp":1773638619372,"version":"3.50.1"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2019,12,17]],"date-time":"2019-12-17T00:00:00Z","timestamp":1576540800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000774","name":"Defense Threat Reduction Agency","doi-asserted-by":"publisher","award":["HDTRA1-13-1-0021, HDTRA1-14-1-0058"],"award-info":[{"award-number":["HDTRA1-13-1-0021, HDTRA1-14-1-0058"]}],"id":[{"id":"10.13039\/100000774","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["AST-1547331, CNS-1617091, CNS-1524317, and CNS-1907905"],"award-info":[{"award-number":["AST-1547331, CNS-1617091, CNS-1524317, and CNS-1907905"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Meas. Anal. Comput. Syst."],"published-print":{"date-parts":[[2019,12,17]]},"abstract":"<jats:p>Volume-based network denial-of-service (DoS) attacks refer to a class of cyber attacks where an adversary seeks to block user traffic from service by sending adversarial traffic that reduces the available user capacity. In this paper, we explore the fundamental limits of volume-based network DoS attacks by studying the minimum required rate of adversarial traffic and investigating optimal attack strategies. We start our analysis with single-hop networks where user traffic is routed to servers following the Join-the-Shortest-Queue (JSQ) rule. Given the service rates of servers and arrival rates of user traffic, we first characterize the feasibility region of the attack and show that the attack is feasible if and only if the rate of the adversarial traffic lies in the region. We then design an attack strategy that is (i).optimal: it guarantees the success of the attack whenever the adversarial traffic rate lies in the feasibility region and (ii).oblivious: it does not rely on knowledge of service rates or user traffic rates. Finally, we extend our results on the feasibility region of the attack and the optimal attack strategy to multi-hop networks that employ Back-pressure (Max-Weight) routing. At a higher level, this paper addresses a class of dual problems of stochastic network stability, i.e., how to optimally de-stabilize a network.<\/jats:p>","DOI":"10.1145\/3366698","type":"journal-article","created":{"date-parts":[[2019,12,18]],"date-time":"2019-12-18T13:21:11Z","timestamp":1576675271000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Fundamental Limits of Volume-based Network DoS Attacks"],"prefix":"10.1145","volume":"3","author":[{"given":"Xinzhe","family":"Fu","sequence":"first","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eytan","family":"Modiano","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,12,17]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"urlhttps:\/\/www.msspalert.com\/cybersecurity-research\/kaspersky-lab-study-average-cost-of-enterprise-ddos-attack-totals-2m\/  urlhttps:\/\/www.msspalert.com\/cybersecurity-research\/kaspersky-lab-study-average-cost-of-enterprise-ddos-attack-totals-2m\/"},{"key":"e_1_2_1_2_1","unstructured":"urlhttps:\/\/www.cloudflare.com\/learning\/ddos\/what-is-a-ddos-attack\/  urlhttps:\/\/www.cloudflare.com\/learning\/ddos\/what-is-a-ddos-attack\/"},{"key":"e_1_2_1_3_1","volume-title":"IEEE communications surveys & tutorials","author":"Zargar T.","unstructured":"T. Zargar , J. Joshi and D. Tipper , \u201c A survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks \u201d, in IEEE communications surveys & tutorials , Vol. 15 , No. 4, pp. 2046--2069, 2013 T. Zargar, J. Joshi and D. Tipper, \u201cA survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks\u201d, in IEEE communications surveys & tutorials, Vol. 15, No. 4, pp. 2046--2069, 2013"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"e_1_2_1_5_1","first-page":"408","volume-title":"IEEE LCN","volume":"10","author":"de Souza Mota E.","year":"2010","unstructured":". Braga, E. de Souza Mota and A. Passito , \u201cLightweight DDoS flooding attack detection using NOX\/OpenFlow \u201d, in IEEE LCN , Vol. 10 pp. 408 -- 415 , 2010 . . Braga, E. de Souza Mota and A. Passito, \u201cLightweight DDoS flooding attack detection using NOX\/OpenFlow\u201d, in IEEE LCN, Vol. 10 pp. 408--415, 2010."},{"key":"e_1_2_1_6_1","first-page":"630","volume-title":"IEEE LCN","author":"Conti M.","year":"2013","unstructured":". Compagno, M. Conti , P. Gasti and G. Tsudik , \u201c Poseidon: Mitigating interest flooding DDoS attacks in named data networking \u201d, in IEEE LCN , pp. 630 -- 638 , 2013 . . Compagno, M. Conti, P. Gasti and G. Tsudik, \u201cPoseidon: Mitigating interest flooding DDoS attacks in named data networking\u201d, in IEEE LCN, pp. 630--638, 2013."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/363647.363659"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539700369168"},{"issue":"4","key":"e_1_2_1_9_1","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1002\/net.1016","article-title":"Stability of networks and protocols in the adversarial queueing model for packet routing","volume":"37","year":"2001","unstructured":". Goel , \u201c Stability of networks and protocols in the adversarial queueing model for packet routing \u201d, in Networks: An International Journal , Vol. 37 , No. 4 , pp. 219 -- 224 , 2001 . . Goel, \u201cStability of networks and protocols in the adversarial queueing model for packet routing\u201d, in Networks: An International Journal, Vol. 37, No. 4, pp.219--224, 2001.","journal-title":"Networks: An International Journal"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.2200\/S00271ED1V01Y201006CNT007"},{"issue":"9","key":"e_1_2_1_11_1","first-page":"12","article-title":"Analysis of join-the-shortest-queue routing for web server farms","volume":"64","author":"Balter M. H.","year":"2007","unstructured":". Gupta, M. H. Balter , K. Sigman and W. Whitt , \u201c Analysis of join-the-shortest-queue routing for web server farms \u201d, in Performance Evaluation , Vol. 64 , No. 9 -- 12 , pp. 1062--1081, 2007 . . Gupta, M. H. Balter, K. Sigman and W. Whitt, \u201cAnalysis of join-the-shortest-queue routing for web server farms\u201d, in Performance Evaluation, Vol. 64, No. 9--12, pp. 1062--1081, 2007.","journal-title":"Performance Evaluation"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.peva.2011.07.015"},{"key":"e_1_2_1_13_1","volume-title":"Deterministic network interdiction. Mathematical and Computer Modelling","author":"Wood K.","unstructured":". K. Wood , \u201c Deterministic network interdiction. Mathematical and Computer Modelling \u201d, Vol. 17 , No. 2, pp. 1--18, 1993 . K. Wood, \u201cDeterministic network interdiction. Mathematical and Computer Modelling\u201d, Vol. 17, No. 2, pp. 1--18, 1993"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/167088.167286"},{"key":"e_1_2_1_15_1","first-page":"1765","volume-title":"IEEE INFOCOM","author":"Modiano E.","year":"2019","unstructured":". Fu and E. Modiano , \u201c Network Interdiction Using Adversarial Traffic Flows \u201d, in IEEE INFOCOM , pp. 1765 -- 1773 , 2019 . . Fu and E. Modiano, \u201cNetwork Interdiction Using Adversarial Traffic Flows\u201d, in IEEE INFOCOM, pp. 1765--1773, 2019."},{"issue":"1","key":"e_1_2_1_16_1","first-page":"13","article-title":"Security game with non-additive utilities and multiple attacker resources","volume":"1","author":"Shroff N.","year":"2017","unstructured":". Wang and N. Shroff , \u201c Security game with non-additive utilities and multiple attacker resources \u201d, in Proc. of the ACM on Measurement and Analysis of Computing Systems , Vol. 1 , No. 1 , pp. 13 , 2017 . Wang and N. Shroff, \u201cSecurity game with non-additive utilities and multiple attacker resources\u201d, in Proc. of the ACM on Measurement and Analysis of Computing Systems, Vol. 1, No. 1, pp.13, 2017","journal-title":"Proc. of the ACM on Measurement and Analysis of Computing Systems"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2480741.2480742"},{"key":"e_1_2_1_18_1","first-page":"2130","volume-title":"IEEE Conference on Decision and Control","author":"Ephremides A.","year":"1990","unstructured":". Tassiulas and A. Ephremides , \u201c Stability properties of constrained queueing systems and scheduling policies for maximum throughput in multihop radio networks \u201d, in IEEE Conference on Decision and Control , pp. 2130 -- 2132 , 1990 . . Tassiulas and A. Ephremides, \u201cStability properties of constrained queueing systems and scheduling policies for maximum throughput in multihop radio networks\u201d, in IEEE Conference on Decision and Control, pp. 2130--2132, 1990."},{"key":"e_1_2_1_19_1","first-page":"594","volume-title":"IEEE INFOCOM","year":"2018","unstructured":". Liang and Modiano, \u201cNetwork utility maximization in adversarial environments \u201d, in IEEE INFOCOM , pp. 594 -- 602 , 2018 . . Liang and Modiano, \u201cNetwork utility maximization in adversarial environments\u201d, in IEEE INFOCOM, pp. 594--602, 2018."},{"issue":"1","key":"e_1_2_1_20_1","first-page":"11","article-title":"Minimizing Queue Length Regret Under Adversarial Network Models","volume":"2","author":"Modiano E.","year":"2018","unstructured":". Liang and E. Modiano , \u201c Minimizing Queue Length Regret Under Adversarial Network Models \u201d, in Proc. of the ACM on Measurement and Analysis of Computing Systems , Vol. 2 , No. 1 , pp. 11 , 2018 . . Liang and E. Modiano, \u201cMinimizing Queue Length Regret Under Adversarial Network Models\u201d, in Proc. of the ACM on Measurement and Analysis of Computing Systems, Vol. 2, No. 1, pp.11, 2018.","journal-title":"Proc. of the ACM on Measurement and Analysis of Computing Systems"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCNS.2016.2550858"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11134-011-9250-1"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1214\/11-AAP759"},{"key":"e_1_2_1_24_1","volume-title":"Topics in the constructive theory of countable Markov chains","author":"Malyshev V. A.","unstructured":". Fayolle, V. A. Malyshev and M. V. Men'shikov , \u201c Topics in the constructive theory of countable Markov chains ,\u201d Cambridge university press , 199 . Fayolle, V. A. Malyshev and M. V. Men'shikov, \u201cTopics in the constructive theory of countable Markov chains,\u201d Cambridge university press, 199"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00453-006-0193-6"},{"issue":"2","key":"e_1_2_1_26_1","first-page":"42","article-title":"Load Balancing Guardrails: Keeping Your Heavy Traffic on the Road to Low Response Times","volume":"3","author":"Scully Z.","year":"2019","unstructured":". Grosof, Z. Scully and M. Harchol-Balter , \u201c Load Balancing Guardrails: Keeping Your Heavy Traffic on the Road to Low Response Times ,\u201d in Proc. of the ACM on Measurement and Analysis of Computing Systems , Vol. 3 , No. 2 , pp. 42 , 2019 . . Grosof, Z. Scully and M. Harchol-Balter, \u201cLoad Balancing Guardrails: Keeping Your Heavy Traffic on the Road to Low Response Times,\u201d in Proc. of the ACM on Measurement and Analysis of Computing Systems, Vol. 3, No. 2, pp. 42, 2019.","journal-title":"Proc. of the ACM on Measurement and Analysis of Computing Systems"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2637364.2592006"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2007.1034"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2006.874401"},{"key":"e_1_2_1_30_1","doi-asserted-by":"crossref","DOI":"10.21236\/ADA594171","volume-title":"Network flows","author":"Ahuja K.","year":"1988","unstructured":". K. Ahuja , T. L. Magnanti and J. B. Orlin , \u201c Network flows \u201d, 1988 . . K. Ahuja, T. L. Magnanti and J. B. Orlin, \u201cNetwork flows\u201d, 1988."}],"container-title":["Proceedings of the ACM on Measurement and Analysis of Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3366698","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3366698","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3366698","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:38Z","timestamp":1750203878000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3366698"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,17]]},"references-count":30,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2019,12,17]]}},"alternative-id":["10.1145\/3366698"],"URL":"https:\/\/doi.org\/10.1145\/3366698","relation":{},"ISSN":["2476-1249"],"issn-type":[{"value":"2476-1249","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,12,17]]},"assertion":[{"value":"2019-12-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}