Denial-of-service (DoS) and distributed denial-of-service (DDoS) mitigation requires separating malicious traffic from benign traffic while minimizing disruption to legitimate users. Prior work proposed mapping honeypot traffic partitioning to a weighted MaxCut problem and solving the resulting graphs with variational quantum algorithms. We extend this proof of principle direction with a reproducible event-level honeypot-to-QUBO pipeline, labeled temporal bipartite benchmark graphs with 16, 32, 66, and 110 event nodes, QAOA executions on IBM quantum hardware, classical heuristic baselines, a noiseless matrix product state reference, and a routing overhead analysis across quantum processor architectures. The largest benchmark is a 110-node, 181-edge instance executed on three IBM backends. Our results show that a shallow QAOA can execute real traffic partitioning workloads at the utility scale, while backend architecture and routing overhead affect objective quality, security metrics, and observed runtime. Because simple classical heuristics can solve the current labeled benchmark graphs, these experiments are not a quantum advantage claim. Instead, we deliberately use a fixed, shallow QAOA implementation to enable controlled comparisons across problem sizes and hardware architectures. This work establishes a hardware feasibility and architecture benchmark framework, and demonstrates that MaxCut cost, security quality, routing overhead, and runtime must be reported as separate metrics for cybersecurity relevant quantum optimization.
翻译:拒绝服务(DoS)与分布式拒绝服务(DDoS)的缓解措施需要将恶意流量与良性流量分离,同时最小化对合法用户的干扰。前期研究提出将蜜罐流量分区问题映射为加权MaxCut问题,并通过变分量子算法求解所得图结构。本研究在原理验证方向上进行扩展,构建了可复现事件级蜜罐到QUBO转化流水线,包含含时间标签的二分基准图(16、32、66、110个事件节点)、IBM量子硬件上的QAOA执行实验、经典启发式基线方法、无噪声矩阵乘积态参考基准,以及跨量子处理器架构的路由开销分析。最大规模基准实例包含110个节点与181条边,在三个IBM后端上运行。结果表明,浅层QAOA可在公用事业规模上执行真实流量分区任务,而后端架构与路由开销会影响目标质量、安全指标及观测运行时间。由于当前标注基准图可通过简单经典启发式方法求解,这些实验并非量子优势声明——我们特意使用固定浅层QAOA实现,以便在问题规模与硬件架构间进行受控对比。本研究建立了硬件可行性与架构基准框架,并论证MaxCut代价、安全质量、路由开销及运行时间必须作为网络安全相关量子优化的独立指标进行报告。