<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T02:44:11Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/122412" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/122412</identifier><datestamp>2021-07-05T14:03:20Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor" lang="en_US">Eytan Modiano.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Fu, Xinzhe.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">Massachusetts Institute of Technology. Department of Aeronautics and Astronautics.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">Massachusetts Institute of Technology. Department of Aeronautics and Astronautics</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2019-10-04T21:33:05Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2019-10-04T21:33:05Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2019</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2019</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/1721.1/122412</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">1119730776</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis: S.M., Massachusetts Institute of Technology, Department of Aeronautics and Astronautics, 2019</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Cataloged from PDF version of thesis.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (pages 107-110).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">A network flow-based attack refers to a cyber-attack where the adversary seeks to block user traffic from transmission by sending adversarial traffic that reduces the available user capacity. In this thesis, we explore the fundamental limits of network flow attacks by investigating its feasibility region defined by the minimum resource required for a successful attack and designing optimal attacking strategies that achieve the feasibility region. First, we consider the case where the target network uses fixed-path routing and the adversary injects traffic into the network, encroaching the capacity of the network links and thus reducing the capacity available to network users on the fixed paths. We propose a new network interdiction paradigm that captures this phenomenon by modeling the network as a capacitated graph with the user throughput given by the max-flow value on the fixed user paths.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">The adversary injects interdicting flows that reduces the capacity of the links (and hence the user throughput), and seeks to maximize the throughput reduction caused by the adversarial injection under a given flow budget. We show the NP-hardness of the problem of maximizing throughput reduction, and propose an efficient approximation algorithm that yields near optimal interdicting flows within a logarithmic factor by harnessing the submodularity of the problem. We further extend the algorithm to an approximation framework that can deal with the situation where the adversary does not have deterministic knowledge of the set of user paths but aims to maximize the worst case throughput reduction given that the set of user paths lies in certain collection of paths. Next, we turn to the scenario where the target network employs dynamic routing mechanisms such as Join-the-Shortest-Queue (JSQ) or Max-Weight.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">We start from single-hop server farm under JSQ routing, where the adversary attacks by injecting adversarial traffic to servers with the objective of blocking user traffic, i.e., causing user traffic to experience unbounded delay. We first characterize the feasibility region of the attack by presenting a necessary and sufficient condition on the rate of adversarial traffic rate for the attack to be successful. We then propose an adversarial injection policy that is, (i) optimal: it achieves a successful attack whenever the adversarial traffic rate is inside the feasibility region and (ii) oblivious: it does not rely on any knowledge of the network statistics. We further evaluate the performance of the injection policy. Finally, we extend our results to multi-hop.network employing Max-Weight routing.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Xinzhe Fu.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">S.M.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="collection" lang="en_US">S.M. Massachusetts Institute of Technology, Department of Aeronautics and Astronautics</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">110 pages</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri" lang="en_US">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Aeronautics and Astronautics.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">Fundamental limit of network flow attacks</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="imported" lang="en_US">2019-10-04T21:33:04Z</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="degree" lang="en_US">Master</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="department" lang="en_US">Aero</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="0e442b00-5af4-4fe5-9c98-ac2b9412a67a">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>Fundamental limit of network flow attacks&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2019&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Fu, Xinzhe.&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>Aeronautics and Astronautics.&lt;/Keyword>
   	&lt;Abstract>A network flow-based attack refers to a cyber-attack where the adversary seeks to block user traffic from transmission by sending adversarial traffic that reduces the available user capacity. In this thesis, we explore the fundamental limits of network flow attacks by investigating its feasibility region defined by the minimum resource required for a successful attack and designing optimal attacking strategies that achieve the feasibility region. First, we consider the case where the target network uses fixed-path routing and the adversary injects traffic into the network, encroaching the capacity of the network links and thus reducing the capacity available to network users on the fixed paths. We propose a new network interdiction paradigm that captures this phenomenon by modeling the network as a capacitated graph with the user throughput given by the max-flow value on the fixed user paths.&lt;/Abstract>
   	&lt;Abstract>The adversary injects interdicting flows that reduces the capacity of the links (and hence the user throughput), and seeks to maximize the throughput reduction caused by the adversarial injection under a given flow budget. We show the NP-hardness of the problem of maximizing throughput reduction, and propose an efficient approximation algorithm that yields near optimal interdicting flows within a logarithmic factor by harnessing the submodularity of the problem. We further extend the algorithm to an approximation framework that can deal with the situation where the adversary does not have deterministic knowledge of the set of user paths but aims to maximize the worst case throughput reduction given that the set of user paths lies in certain collection of paths. Next, we turn to the scenario where the target network employs dynamic routing mechanisms such as Join-the-Shortest-Queue (JSQ) or Max-Weight.&lt;/Abstract>
   	&lt;Abstract>We start from single-hop server farm under JSQ routing, where the adversary attacks by injecting adversarial traffic to servers with the objective of blocking user traffic, i.e., causing user traffic to experience unbounded delay. We first characterize the feasibility region of the attack by presenting a necessary and sufficient condition on the rate of adversarial traffic rate for the attack to be successful. We then propose an adversarial injection policy that is, (i) optimal: it achieves a successful attack whenever the adversarial traffic rate is inside the feasibility region and (ii) oblivious: it does not rely on any knowledge of the network statistics. We further evaluate the performance of the injection policy. Finally, we extend our results to multi-hop.network employing Max-Weight routing.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>