ACM Home Page
Please provide us with feedback. Feedback
Message Dropping Attacks in Overlay Networks: Attack Detection and Attacker Identification
Full text PdfPdf (842 KB)
Source
ACM Transactions on Information and System Security (TISSEC) archive
Volume 11 ,  Issue 3  (March 2008) table of contents
Article No. 15  
Year of Publication: 2008
ISSN:1094-9224
Authors
Liang Xie  The Pennsylvania State University
Sencun Zhu  The Pennsylvania State University
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 16,   Downloads (12 Months): 180,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1341731.1341736
What is a DOI?

ABSTRACT

Overlay multicast networks are used by service providers to distribute contents such as Web pages, static and streaming multimedia data, or security updates to a large number of users. However, such networks are extremely vulnerable to message-dropping attacks by malicious or selfish nodes that intentionally drop the packets they are required to forward to others. It is difficult to detect such attacks both efficiently and effectively and to further identify the attackers, especially when members in the overlay switch between online/offline statuses frequently. In this article, we consider various attacking strategies of an attacker and propose an optimal sampling-based scheme to detect such attacks in the overlay network. We analyze the detection problem from a game-theoretical viewpoint and show that our scheme outperforms a random sampling-based scheme in terms of detection rate. In addition, based on a reputation system, we propose a sampling-based path-resolving scheme to identify compromised or selfish nodes. Unlike other existing approaches, our schemes do not assume global knowledge of the overlay hierarchy and work for dynamic overlay networks as well. Extensive analysis and simulation results show that besides being band width efficient, our schemes have high detection and identification rates and low false-positive rates.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Almeroth, K. and Ammar, M. 1997. Multicast group behavior in the Internet's multicast bckbone (mbone). IEEE Comm.
2
3
4
 
5
 
6
 
7
Buchegger, S. and Boudec, J. 2004. A robust reputation system for p2p and mobile ad-hoc networks. In Proceedings of 2nd Workshop of Economics of P2P Systems.
8
9
 
10
CSIM. Web site at www.mesquite.com.
 
11
 
12
Drabkin, V., Wallach, D., and Druschel, P. 2005. Incentives-compatible peer-to-peer multicast. In Proceedings of the International Conference on Dependable Systems and Networks (DSN'05).
13
14
 
15
 
16
 
17
 
18
Mathy, L., Blundell, N., Roca, V., and El-Sayed, A. 2004. Impact of simple cheating in application-level multicast. In Proceedings of the Annual Joint Conference of the IEEE Computer and Communication Societies (INFOCOM), 2, 1318--1328.
 
19
Ngan, T., Wallach, S., and Druschel, P. 2004. Incentives-compatible peer-to-peer multicast. 2nd Workshop on Economics of Peer-to-Peer Systems.
20
 
21
Palter, D. Sept. 2002. Multicast fan-out saves bandwidth. Network World.
 
22
 
23
Reiher, J. and Popek, G. 2004. Resilient self-organizing overlay networks for security update delivery. IEEE J. Selec. Areas Comm.
 
24
 
25
 
26
27
 
28
 
29
Zhang, B., Jamin, S., and Zhang, L. 2002. Host multicast: A framework for delivering multicast to end users. In Proceedings of the Annual Joint Conference of the IEEE Computer and Communication Societies (INFOCOM). 1366--1375.
 
30
Zhu, S., Yao, C., Liu, D., Setia, S., and Jajodia, S. 2005. Efficient security mechanisms for overlay multicast-based content distribution. In Proceedings of International Conference on Applied Cryptography and Network Security (ACNS'05). 40--55.