Enhancing Resiliency of Sketch-based Security via LSB Sharing-based Dynamic Late Merging
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866912276602159104 |
|---|---|
| author | Yang, Seungsam Mirnajafizadeh, Seyed Mohammad Mehdi Kim, Sian Jang, Rhongho Nyang, DaeHun |
| author_facet | Yang, Seungsam Mirnajafizadeh, Seyed Mohammad Mehdi Kim, Sian Jang, Rhongho Nyang, DaeHun |
| contents | With the exponentially growing Internet traffic, sketch data structure with a probabilistic algorithm has been expected to be an alternative solution for non-compromised (non-selective) security monitoring. While facilitating counting within a confined memory space, the sketch's memory efficiency and accuracy were further pushed to their limit through finer-grained and dynamic control of constrained memory space to adapt to the data stream's inherent skewness (i.e., Zipf distribution), namely small counters with extensions. In this paper, we unveil a vulnerable factor of the small counter design by introducing a new sketch-oriented attack, which threatens a stream of state-of-the-art sketches and their security applications. With the root cause analyses, we propose Siamese Counter with enhanced adversarial resiliency and verified feasibility with extensive experimental and theoretical analyses. Under a sketch pollution attack, Siamese Counter delivers 47% accurate results than a state-of-the-art scheme, and demonstrates up to 82% more accurate estimation under normal measurement scenarios. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2503_11777 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Enhancing Resiliency of Sketch-based Security via LSB Sharing-based Dynamic Late Merging Yang, Seungsam Mirnajafizadeh, Seyed Mohammad Mehdi Kim, Sian Jang, Rhongho Nyang, DaeHun Cryptography and Security Networking and Internet Architecture With the exponentially growing Internet traffic, sketch data structure with a probabilistic algorithm has been expected to be an alternative solution for non-compromised (non-selective) security monitoring. While facilitating counting within a confined memory space, the sketch's memory efficiency and accuracy were further pushed to their limit through finer-grained and dynamic control of constrained memory space to adapt to the data stream's inherent skewness (i.e., Zipf distribution), namely small counters with extensions. In this paper, we unveil a vulnerable factor of the small counter design by introducing a new sketch-oriented attack, which threatens a stream of state-of-the-art sketches and their security applications. With the root cause analyses, we propose Siamese Counter with enhanced adversarial resiliency and verified feasibility with extensive experimental and theoretical analyses. Under a sketch pollution attack, Siamese Counter delivers 47% accurate results than a state-of-the-art scheme, and demonstrates up to 82% more accurate estimation under normal measurement scenarios. |
| title | Enhancing Resiliency of Sketch-based Security via LSB Sharing-based Dynamic Late Merging |
| topic | Cryptography and Security Networking and Internet Architecture |
| url | https://arxiv.org/abs/2503.11777 |