A Moving Target DDoS Defense Approach in Consortium Blockchain

Keke Gai*, Guolei Zhang, Peng Jiang, Liehuang Zhu, Kim Kwang Raymond Choo

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

摘要

Although consortium blockchain has an identification mechanism, the captured internal clients are potentially threatening internal blockchain nodes. Internal Distributed Denial-of-Service (DDoS) attacks threaten the specific nodes in consortium blockchain, e.g., the executor, consensus, and committer nodes. Typical attack methods may include SYN Flooding and ACK Flooding and deny normal transaction service by sending many invalid transactions and blocks. In this work, we have proposed an organization collaboration-based DDoS defense approach and a Deep Q-learning (DQN)-based Moving Target Defense (MTD) for changing attack surface of victims in consortium blockchain. On one hand, contracts are used to synchronize attack information obtained from organizations, e.g., bots' IP addresses and public keys. On the other hand, we have developed a DQN-based MTD defense mechanism for organizations to change the attack surface of victims in order to mitigate the malicious traffic, in the case of missing detections of bots. Our approach applies a multi-stage game to reflect interactions between attackers and defenders. The evaluation results have demonstrated that our approach could effectively mitigate DDoS attacks in consortium blockchain.

指纹

探究 'A Moving Target DDoS Defense Approach in Consortium Blockchain' 的科研主题。它们共同构成独一无二的指纹。

引用此

Gai, K., Zhang, G., Jiang, P., Zhu, L., & Choo, K. K. R. (已接受/印刷中). A Moving Target DDoS Defense Approach in Consortium Blockchain. IEEE Transactions on Dependable and Secure Computing. https://doi.org/10.1109/TDSC.2025.3546625