首页> 外文会议>Applied Cryptography and Network Security >Pushback for Overlay Networks: Protecting Against Malicious Insiders
【24h】

Pushback for Overlay Networks: Protecting Against Malicious Insiders

机译:覆盖网络的推回:防范恶意内部人员

获取原文
获取原文并翻译 | 示例

摘要

Peer-to-Peer (P2P) overlay networks are a flexible way of creating decentralized services. Although resilient to external Denial of Service attacks, overlay networks can be rendered inoperable by simple flooding attacks generated from insider nodes. In this paper, we study detection and containment mechanisms against insider Denial of Service (DoS) attacks for overlay networks. To counter such attacks, we introduce novel mechanisms for protecting overlay networks that exhibit well defined properties due to their structure against non-conforming (abnormal) behavior of participating nodes. We use a lightweight distributed detection mechanism that exploits inherent structural invariants of DHTs to ferret out anomalous flow behavior. We evaluate our mechanism's ability to detect attackers using our prototype implementation on web traces from IRCache served by a DHT network. Our results show that our system can detect a simple attacker whose attack traffic deviates by as little as 5% from average traffic. We also demonstrate the resiliency of our mechanism against coordinated distributed flooding attacks that involve up to 15% of overlay nodes. In addition, we verify that our detection algorithms work well, producing a low false positive rate (< 2%) when used in a system that serves normal web traffic.
机译:对等(P2P)覆盖网络是创建分散服务的灵活方式。尽管可以抵御外部拒绝服务攻击,但是通过内部节点生成的简单泛洪攻击可以使覆盖网络无法运行。在本文中,我们研究了针对覆盖网络的内部拒绝服务(DoS)攻击的检测和遏制机制。为了应对此类攻击,我们引入了新颖的机制来保护覆盖网络,这些覆盖网络因其结构免受参与节点的不合格(异常)行为而表现出良好定义的属性。我们使用轻量级的分布式检测机制,该机制利用DHT的固有结构不变性来发现异常流行为。我们使用原型实现在DHT网络提供服务的IRCache上的Web跟踪上评估我们的机制检测攻击者的能力。我们的结果表明,我们的系统可以检测到一个简单的攻击者,其攻击流量与平均流量的偏差仅为5%。我们还展示了我们的机制对涉及多达15%的覆盖节点的协同分布式洪水攻击的弹性。此外,我们验证了我们的检测算法是否工作正常,在用于正常网络流量的系统中使用时,产生的假阳性率较低(<2%)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号