An intelligent proactive defense against the client‐side DNS cache poisoning attack via self‐checking deep reinforcement learning. Issue 10 (27th May 2022)
- Record Type:
- Journal Article
- Title:
- An intelligent proactive defense against the client‐side DNS cache poisoning attack via self‐checking deep reinforcement learning. Issue 10 (27th May 2022)
- Main Title:
- An intelligent proactive defense against the client‐side DNS cache poisoning attack via self‐checking deep reinforcement learning
- Authors:
- Ma, Tengchao
Xu, Changqiao
Yang, Shujie
Huang, Yiting
Kuang, Xiaohui
Tang, Hong
Grieco, Luigi Alfredo - Abstract:
- Abstract: A new class of poisoning attacks has recently emerged targeting the client‐side Domain Name System (DNS) cache. It allows users to visit fake websites unconsciously, thereby revealing their information, such as passwords. However, the current DNS defense architecture does not include DNS clients. Although relative encryption solutions can mitigate this attack, they require the cooperation of multiple parties, and the deployment speed is slow. Therefore, we propose an intelligent‐driven proactive defense strategy. First, we model the offensive and defensive process as a stochastic game based on moving target defense. Second, we adopt and optimize Proximal Policy Optimization (PPO), a deep reinforcement learning method, to solve problems caused by uncertain attack strategies and unknown state transition probability. Third, we design a self‐checking component in PPO to solve the uncertainty of action space caused by game state constraints based on our previous work. Thus the convergence speed and stability of PPO are improved. Finally, to the best of our knowledge, we are the first to game with intelligent attackers besides three conventional ones. Our strategy does not require any modifications to the DNS architecture. Through an extensive experimental campaign, the prototype system is proved to be effective against multiple attack modes. Its success rate is 98.5% approximately, and network round‐trip time is about 55 ms. Even for random attackers, our method canAbstract: A new class of poisoning attacks has recently emerged targeting the client‐side Domain Name System (DNS) cache. It allows users to visit fake websites unconsciously, thereby revealing their information, such as passwords. However, the current DNS defense architecture does not include DNS clients. Although relative encryption solutions can mitigate this attack, they require the cooperation of multiple parties, and the deployment speed is slow. Therefore, we propose an intelligent‐driven proactive defense strategy. First, we model the offensive and defensive process as a stochastic game based on moving target defense. Second, we adopt and optimize Proximal Policy Optimization (PPO), a deep reinforcement learning method, to solve problems caused by uncertain attack strategies and unknown state transition probability. Third, we design a self‐checking component in PPO to solve the uncertainty of action space caused by game state constraints based on our previous work. Thus the convergence speed and stability of PPO are improved. Finally, to the best of our knowledge, we are the first to game with intelligent attackers besides three conventional ones. Our strategy does not require any modifications to the DNS architecture. Through an extensive experimental campaign, the prototype system is proved to be effective against multiple attack modes. Its success rate is 98.5% approximately, and network round‐trip time is about 55 ms. Even for random attackers, our method can achieve the theoretical maximum defensive success rate. … (more)
- Is Part Of:
- International journal of intelligent systems. Volume 37:Issue 10(2022)
- Journal:
- International journal of intelligent systems
- Issue:
- Volume 37:Issue 10(2022)
- Issue Display:
- Volume 37, Issue 10 (2022)
- Year:
- 2022
- Volume:
- 37
- Issue:
- 10
- Issue Sort Value:
- 2022-0037-0010-0000
- Page Start:
- 8170
- Page End:
- 8197
- Publication Date:
- 2022-05-27
- Subjects:
- client‐side DNS cache poisoning attack -- deep reinforcement learning -- intelligent defense system -- moving target defense
Artificial intelligence -- Periodicals
Expert systems (Computer science) -- Periodicals
Intelligence artificielle -- Périodiques
Systèmes experts (Informatique) -- Périodiques
006.3 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1098-111X ↗
https://www.hindawi.com/journals/ijis ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/int.22934 ↗
- Languages:
- English
- ISSNs:
- 0884-8173
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.310500
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 23202.xml