A lightweight mechanism for detection of cache pollution attacks in Named Data Networking

被引:111
|
作者
Conti, Mauro [1 ]
Gasti, Paolo [2 ]
Teoli, Marco [1 ]
机构
[1] Univ Padua, Dept Math, I-35131 Padua, Italy
[2] New York Inst Technol, Sch Engn & Comp Sci, New York, NY 10023 USA
基金
美国国家科学基金会;
关键词
Named data networking; Cache pollution attack; Security;
D O I
10.1016/j.comnet.2013.07.034
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Content-Centric Networking (CCN) is an emerging paradigm being considered as a possible replacement for the current IP-based host-centric Internet infrastructure. In CCN, named content - rather than addressable hosts - becomes a first-class entity. Content is therefore decoupled from its location. This allows, among other things, the implementation of ubiquitous caching. Named-Data Networking (NON) is a prominent example of CCN. In NON, all nodes (i.e., hosts, routers) are allowed to have a local cache, used to satisfy incoming requests for content. This makes NDN a good architecture for efficient large scale content distribution. However, reliance on caching allows an adversary to perform attacks that are very effective and relatively easy to implement. Such attacks include cache poisoning (i.e., introducing malicious content into caches) and cache pollution (i.e., disrupting cache locality). This paper focuses on cache pollution attacks, where the adversary's goal is to disrupt cache locality to increase link utilization and cache misses for honest consumers. We show, via simulations, that such attacks can be implemented in NON using limited resources, and that their effectiveness is not limited to small topologies. We then illustrate that existing proactive countermeasures are ineffective against realistic adversaries. Finally, we introduce a new technique for detecting pollution attacks. Our technique detects high and low rate attacks on different topologies with high accuracy. (C) 2013 Elsevier B.V. All rights reserved.
引用
收藏
页码:3178 / 3191
页数:14
相关论文
共 50 条
  • [1] Collaborative detection mechanism for low-rate cache pollution attack in named data networking
    Zhu, Yi
    Shi, Jia
    Gong, Pu
    Cao, Qing-Hua
    Su, Dong
    Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2015, 38 (06): : 44 - 48
  • [2] An ANFIS-based cache replacement method for mitigating cache pollution attacks in Named Data Networking
    Karami, Amin
    Guerrero-Zapata, Mane
    COMPUTER NETWORKS, 2015, 80 : 51 - 65
  • [3] Detection and Defense of Cache Pollution Based on Popularity Prediction in Named Data Networking
    Yao, Lin
    Zeng, Yujie
    Wang, Xin
    Chen, Ailun
    Wu, Guowei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (06) : 2848 - 2860
  • [4] Detection and Defense of Cache Pollution Attacks Using Clustering in Named Data Networks
    Yao, Lin
    Fan, Zhenzhen
    Deng, Jing
    Fan, Xin
    Wu, Guowei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2020, 17 (06) : 1310 - 1321
  • [5] A Detection Mechanism for Cache Pollution Attack in Named Data Network Architecture
    Hidouri, Abdelhak
    Touati, Haifa
    Hadded, Mohamed
    Hajlaoui, Nasreddine
    Muhlethaler, Paul
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 1, 2022, 449 : 435 - 446
  • [6] Multi-classifier and meta-heuristic based cache pollution attacks and interest flooding attacks detection and mitigation model for named data networking
    Buvanesvari, R.
    Joseph, Suresh K.
    JOURNAL OF EXPERIMENTAL & THEORETICAL ARTIFICIAL INTELLIGENCE, 2024, 36 (06) : 839 - 864
  • [7] A Method for Joint Detection of Attacks in Named Data Networking
    Wu Z.
    Zhang R.
    Yue M.
    1600, Science Press (58): : 569 - 582
  • [8] Exploiting Path Diversity for Thwarting Pollution Attacks in Named Data Networking
    Guo, Haoran
    Wang, Xiaodong
    Chang, Kun
    Tian, Ye
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (09) : 2077 - 2090
  • [9] RBFNN: a radial basis function neural network model for detecting and mitigating the cache pollution attacks in named data networking
    Buvanesvari, Ramachandira Moorthy
    Suresh Joseph, Kanagaraj
    IET NETWORKS, 2020, 9 (05) : 255 - 261
  • [10] ELDA: Towards Efficient and Lightweight Detection of Cache Pollution Attacks in NDN
    Xu, Zhiwei
    Chen, Bo
    Wang, Ninghan
    Zhang, Yujun
    Li, Zhongcheng
    40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 82 - 90