...
首页> 外文期刊>ACM Transaction on Information and System Security >Practical Defenses Against Pollution Attacks in Wireless Network Coding
【24h】

Practical Defenses Against Pollution Attacks in Wireless Network Coding

机译:无线网络编码中针对污染攻击的实用防御

获取原文
获取原文并翻译 | 示例
           

摘要

Recent studies have shown that network coding can provide significant benefits to network protocols, such as increased throughput, reduced network congestion, higher reliability, and lower power consumption. The core principle of network coding is that intermediate nodes actively mix input packets to produce output packets. This mixing subjects network coding systems to a severe security threat, known as a pollution attack, where attacker nodes inject corrupted packets into the network. Corrupted packets propagate in an epidemic manner, depleting network resources and significantly decreasing throughput. Pollution attacks are particularly dangerous in wireless networks, where attackers can easily inject packets or compromise devices due to the increased network vulnerability. In this article, we address pollution attacks against network coding systems in wireless mesh networks. We demonstrate that previous solutions are impractical in wireless networks, incurring an unacceptable high degradation of throughput. We propose a lightweight scheme, DART, that uses time-based authentication in combination with random linear transformations to defend against pollution attacks. We further improve system performance and propose EDART, which enhances DART with an optimistic forwarding scheme. We also propose efficient attacker identification schemes for both DART and EDART that enable quick attacker isolation and the selection of attacker-free paths, achieving additional performance improvement. A detailed security analysis shows that the probability of a polluted packet passing our verification procedure is very low (less than 0.002% in typical settings). Performance results using the well-known MORE protocol and realistic link quality measurements from the Roofnet experimental testbed show that our schemes improve system performance over 20 times compared with previous solutions.
机译:最近的研究表明,网络编码可以为网络协议提供显着的好处,例如增加吞吐量,减少网络拥塞,提高可靠性和降低功耗。网络编码的核心原理是中间节点主动混合输入数据包以产生输出数据包。这种混合使网络编码系统遭受严重的安全威胁,称为污染攻击,攻击者节点在其中将损坏的数据包注入网络。损坏的数据包以流行方式传播,从而耗尽网络资源并显着降低吞吐量。污染攻击在无线网络中尤其危险,由于网络漏洞的增加,攻击者可以轻松地注入数据​​包或破坏设备。在本文中,我们解决了针对无线网状网络中网络编码系统的污染攻击。我们证明了先前的解决方案在无线网络中是不切实际的,从而导致吞吐量的不可接受的高度降低。我们提出了一种轻型方案DART,该方案将基于时间的身份验证与随机线性变换结合使用,以防御污染攻击。我们进一步提高了系统性能,并提出了EDART,它通过一种乐观的转发方案增强了DART。我们还针对DART和EDART提出了有效的攻击者识别方案,该方案可实现快速的攻击者隔离和无攻击者路径的选择,从而进一步提高性能。详细的安全分析表明,受污染的数据包通过我们的验证程序的可能性非常低(典型设置中小于0.002%)。使用著名的MORE协议和Roofnet实验测试台的实际链路质量测量得出的性能结果表明,与以前的解决方案相比,我们的方案将系统性能提高了20倍以上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号