ZUbers against ZLyfts Apocalypse: An Analysis Framework for DoS Attacks on Mobility-As-A-Service Systems

Chenyang Yuan, Jérôme Thai, A. Bayen
{"title":"ZUbers against ZLyfts Apocalypse: An Analysis Framework for DoS Attacks on Mobility-As-A-Service Systems","authors":"Chenyang Yuan, Jérôme Thai, A. Bayen","doi":"10.1109/ICCPS.2016.7479132","DOIUrl":null,"url":null,"abstract":"The vulnerability of Mobility-as-a-Service (MaaS) systems to Denial-of-Service (DoS) attacks is studied. We use a queuing-theoretical framework to model the re-dispatch process used by operators to maintain a high service availability, as well as potential cyber-attacks on this process. It encompasses a customer arrival rate model at different sections of an urban area to pick up vehicles traveling within the network. Expanding this re-balance model, we analyze DoS cyber-attacks of MaaS systems by controlling a fraction of the cars maliciously through fake reservations (so called Zombies) placed in the system (similar to the computer science field where a Zombie is a computer that a remote attacker has accessed for malicious purpose). The attacker can then use the block-coordinate descent algorithm proposed in the present work to derive optimal strategies to minimize the efficiency of the MaaS system, thereby allowing us to quantify the economic loss of such systems under attack. The technique is shown to work well and enables us to arbitrarily deplete taxi availabilities based on the attacker's choice and the radius of attacks, which is demonstrated by drawing a \"Cal\" logo in Manhattan. Finally, a cost-benefit analysis using data from 75 million taxi trips shows diminishing returns for the attacker and that countermeasures raising the attack cost to more than $15 could protect MaaS systems in NYC from Zombies.","PeriodicalId":6619,"journal":{"name":"2016 ACM/IEEE 7th International Conference on Cyber-Physical Systems (ICCPS)","volume":"7 1","pages":"1-10"},"PeriodicalIF":0.0000,"publicationDate":"2016-04-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 ACM/IEEE 7th International Conference on Cyber-Physical Systems (ICCPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCPS.2016.7479132","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

The vulnerability of Mobility-as-a-Service (MaaS) systems to Denial-of-Service (DoS) attacks is studied. We use a queuing-theoretical framework to model the re-dispatch process used by operators to maintain a high service availability, as well as potential cyber-attacks on this process. It encompasses a customer arrival rate model at different sections of an urban area to pick up vehicles traveling within the network. Expanding this re-balance model, we analyze DoS cyber-attacks of MaaS systems by controlling a fraction of the cars maliciously through fake reservations (so called Zombies) placed in the system (similar to the computer science field where a Zombie is a computer that a remote attacker has accessed for malicious purpose). The attacker can then use the block-coordinate descent algorithm proposed in the present work to derive optimal strategies to minimize the efficiency of the MaaS system, thereby allowing us to quantify the economic loss of such systems under attack. The technique is shown to work well and enables us to arbitrarily deplete taxi availabilities based on the attacker's choice and the radius of attacks, which is demonstrated by drawing a "Cal" logo in Manhattan. Finally, a cost-benefit analysis using data from 75 million taxi trips shows diminishing returns for the attacker and that countermeasures raising the attack cost to more than $15 could protect MaaS systems in NYC from Zombies.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
ZUbers对抗ZLyfts启示:移动即服务系统DoS攻击的分析框架
研究了移动即服务(MaaS)系统在DoS攻击下的脆弱性。我们使用排队理论框架来模拟运营商用于维持高服务可用性的重新调度过程,以及对该过程的潜在网络攻击。它包含了一个客户到达率模型,在一个城市地区的不同部分,以挑选在网络内行驶的车辆。扩展这个重新平衡模型,我们通过放置在系统中的假预订(所谓的僵尸)恶意控制一小部分汽车来分析MaaS系统的DoS网络攻击(类似于计算机科学领域,僵尸是远程攻击者出于恶意目的访问的计算机)。然后,攻击者可以使用本工作中提出的块坐标下降算法来推导最优策略,以最大限度地降低MaaS系统的效率,从而使我们能够量化攻击下此类系统的经济损失。该技术被证明工作良好,使我们能够根据攻击者的选择和攻击半径任意耗尽出租车可用性,这是通过在曼哈顿绘制“Cal”标志来证明的。最后,使用7500万次出租车行程数据进行的成本效益分析显示,攻击者的收益递减,而将攻击成本提高到15美元以上的对策可以保护纽约市的MaaS系统免受僵尸攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
ICCPS '21: ACM/IEEE 12th International Conference on Cyber-Physical Systems, Nashville, Tennessee, USA, May 19-21, 2021 Demo Abstract: SURE: An Experimentation and Evaluation Testbed for CPS Security and Resilience Poster Abstract: Thermal Side-Channel Forensics in Additive Manufacturing Systems Exploiting Wireless Channel Randomness to Generate Keys for Automotive Cyber-Physical System Security WiP Abstract: Platform for Designing and Managing Resilient and Extensible CPS
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1