Network Topology Obfuscation: Challenges, Solutions, and Comparisons
Attackers infer the network topology to locate critical components and to plan cost-effective attacks with high success rates. Network topology obfuscation (NTO) counters this by exposing a well-designed fake topology that misleads the inference and raises the cost of attack. Existing surveys cover topology inference but give limited attention to proactive defense. We disassemble the NTO mechanisms into three workflow phases, identification, generation and deployment, and into four fundamental techniques, rerouting, virtual network, response fabricating and packet intervention, whose combination forms each of them. We then systematically analyze multiple NTO mechanisms by technique and design objective, and outline future research directions.
Authors
- Lailong Luo (ORCID: https://orcid.org/0000-0002-4886-9974)
- Bangbang Ren (ORCID: https://orcid.org/0000-0003-0355-0545)
- Deke Guo (ORCID: https://orcid.org/0000-0003-4894-5540)
- Changhao Qiu (ORCID: https://orcid.org/0009-0006-2810-5017)
Institutions
- Sun Yat-sen University (CN)
- National University of Defense Technology (CN)
Publication Details
- Journal
- ACM Computing Surveys
- Published
- 2026-10-08
- DOI
- https://doi.org/10.1145/3857909
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00