arXiv:2512.23849cs.CRcs.AI2025-12被引 1

用经济成本阻击攻击,让黑客干不下去,适合资源受限的物联网设备。

Security Without Detection: Economic Denial as a Primitive for Edge and IoT Defense

  • 通过计算谜题、诱饵交互等四机制让攻击成本超线性上升
  • 实测攻击速度大幅下降,成功率降低,仅增20毫秒延迟
  • 无需检测即可防御,特别适合微控制器等小设备

复杂攻击者可利用加密、隐蔽手段和低速攻击模式绕过检测,尤其在资源有限的物联网(IoT)和边缘环境中,基于机器学习的入侵检测系统难以部署。本文提出经济拒止安全(EDS)框架,不依赖检测,而是使攻击在经济上不可行。该框架利用攻防双方环境控制权的根本不对称性,通过自适应计算谜题、诱饵驱动交互熵、时间拉伸和带宽征税四种机制,实现攻击成本超线性放大。利用博弈论证明了EDS最优配置,发现组合使用多个机制的成本约为单独使用的2.1倍,是设计中的关键权衡。令人欣慰的是,EDS极为高效,内存占用低于12 KB,可在微控制器等嵌入式设备上运行。在20种不同IoT设备上,针对四种攻击场景的测试显示,攻击显著放缓,成本失衡,成功率下降,系统仅增加20毫秒延迟且无误报。与机器学习检测结合后,对真实恶意软件(Mirai、Torii、Hajime)的防护率从67%提升至88%,两者协同可达94%,整体提升27%。相比传统检测方法,EDS独立运行,无需识别攻击,适用于其他方案无法落地的资源受限场景。

原文摘要 · Abstract (English)

Sophisticated attackers can evade detection-based security by using encryption, stealth tactics, and low-rate attack patterns. This challenge is particularly acute in Internet of Things (IoT) and edge environments, where limited resources make ML-based intrusion detection systems impractical. Hereby, we present Economic Denial Security (EDS), a framework that renders attacks economically infeasible rather than trying to detect them. EDS exploits a fundamental asymmetry. Defenders control their own environment, whereas attackers do not. The four mechanisms in this framework amplify attack costs superlinearly. These mechanisms include adaptive computational puzzles, decoy-driven interaction entropy, temporal stretching, and bandwidth taxation. This paper uses game theory to mathematically prove the optimal configuration of EDS, and we found that combining multiple safety mechanisms usually costs 2.1 times as much as using them separately, a key trade-off to consider during design. The good news is that EDS is extremely efficient, using less than 12 KB of memory, making it practical to run on small embedded devices like microcontrollers rather than on expensive servers. EDS is tested on 20 different IoT devices under four attack scenarios. The results showed that attacks slow down significantly, costs become asymmetric, attack success rates drop, and the system adds only 20 ms of latency with no false positive results. When tested against real malware (Mirai, Torii, and Hajime), combining EDS with machine learning detection improved protection from 67 % to 88 %. Adding both techniques together reached 94 % protection, a 27 % improvement overall. Unlike traditional detection-based approaches, EDS operates independently, without requiring attack identification, making it practical for resource-limited IoT devices where other methods simply don't work.

物联网安全经济拒止轻量级防御边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。