The distributed nature of multi-tier swarm attacks renders it more difficult for a single-tier intrusion detection system (IDS) to secure cross-tier computation offloading in multi-tier sensor edge cloud (SEC). To perceive and prevent such attacks, we model IDSs in different layers as an IDS federation network (IDFN) and present a generic framework to prevent cooperative attacks and reconfigure the defense strategy of IDFN across the three-tier SEC. The framework provides single-tier, two-tier, and three-tier dynamic awareness models based on the susceptible-infected-susceptible (SIS) dynamical equations to characterize the update process of message states to obtain the equilibrium solution between alarm messages and normal messages captured by IDSs. For swarm attack events from multi-tier SEC, we model the cross-tier cooperative interactions between IDSs and swarm attackers as an event-condition-action (ECA) regret learning game (ERLG) to achieve a distributed IDS reconfiguration to reduce the overall SEC alarm messages while ensuring the equilibrium of message states with the cooperation of IDSs. Simulation results demonstrate that our proposed scheme is superior to other reconfiguration mechanisms under swarm attacks in three-tier SEC.
Read full abstract