TY - GEN
T1 - Triarchy-Based for DDoS-Resilient IoT Networks
AU - Javadpour, Amir
AU - Ja'fari, Forough
AU - Taleb, Tarik
AU - Benzaid, Chafika
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Identifying cost-effective attack scenarios in large-scale IoT networks from an adversarial perspective is vital for proactive defense planning, since protecting even a subset of nodes can significantly improve overall resilience. However, no dedicated algorithm currently pinpoints the most efficient attack paths under realistic cost constraints. In this paper, we introduce a new graph structure, the triarchy graph, to formalize cost-efficient attack-path identification and establish the problem's NP-completeness. Building on this formulation, we propose CRL-MTD, a cost-effective reinforcement learning (RL)-based moving target defense strategy that learns to identify high-impact attack paths and strategically perturbs them to delay adversaries while minimizing operational burden. We evaluate CRL-MTD on real-world SNDlib-based IoT topologies under simulated Mirai botnet attacks. Experimental results show that CRL-MTD improves solution efficiency by 15%, increases attack execution delay by 111%, and reduces system overhead by 90% compared with representative baseline approaches, demonstrating strong practicality for DDoS-resilient IoT deployments.
AB - Identifying cost-effective attack scenarios in large-scale IoT networks from an adversarial perspective is vital for proactive defense planning, since protecting even a subset of nodes can significantly improve overall resilience. However, no dedicated algorithm currently pinpoints the most efficient attack paths under realistic cost constraints. In this paper, we introduce a new graph structure, the triarchy graph, to formalize cost-efficient attack-path identification and establish the problem's NP-completeness. Building on this formulation, we propose CRL-MTD, a cost-effective reinforcement learning (RL)-based moving target defense strategy that learns to identify high-impact attack paths and strategically perturbs them to delay adversaries while minimizing operational burden. We evaluate CRL-MTD on real-world SNDlib-based IoT topologies under simulated Mirai botnet attacks. Experimental results show that CRL-MTD improves solution efficiency by 15%, increases attack execution delay by 111%, and reduces system overhead by 90% compared with representative baseline approaches, demonstrating strong practicality for DDoS-resilient IoT deployments.
UR - https://www.scopus.com/pages/publications/105045345702
U2 - 10.1109/ICC59461.2026.11587118
DO - 10.1109/ICC59461.2026.11587118
M3 - 会议稿件
AN - SCOPUS:105045345702
T3 - IEEE International Conference on Communications
BT - ICC 2026 - IEEE International Conference on Communications, Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2026 IEEE International Conference on Communications, ICC 2026
Y2 - 24 May 2026 through 28 May 2026
ER -