A lightweight mechanism for detection of cache pollution attacks in Named Data Networking

被引:111
|
作者
Conti, Mauro [1 ]
Gasti, Paolo [2 ]
Teoli, Marco [1 ]
机构
[1] Univ Padua, Dept Math, I-35131 Padua, Italy
[2] New York Inst Technol, Sch Engn & Comp Sci, New York, NY 10023 USA
基金
美国国家科学基金会;
关键词
Named data networking; Cache pollution attack; Security;
D O I
10.1016/j.comnet.2013.07.034
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Content-Centric Networking (CCN) is an emerging paradigm being considered as a possible replacement for the current IP-based host-centric Internet infrastructure. In CCN, named content - rather than addressable hosts - becomes a first-class entity. Content is therefore decoupled from its location. This allows, among other things, the implementation of ubiquitous caching. Named-Data Networking (NON) is a prominent example of CCN. In NON, all nodes (i.e., hosts, routers) are allowed to have a local cache, used to satisfy incoming requests for content. This makes NDN a good architecture for efficient large scale content distribution. However, reliance on caching allows an adversary to perform attacks that are very effective and relatively easy to implement. Such attacks include cache poisoning (i.e., introducing malicious content into caches) and cache pollution (i.e., disrupting cache locality). This paper focuses on cache pollution attacks, where the adversary's goal is to disrupt cache locality to increase link utilization and cache misses for honest consumers. We show, via simulations, that such attacks can be implemented in NON using limited resources, and that their effectiveness is not limited to small topologies. We then illustrate that existing proactive countermeasures are ineffective against realistic adversaries. Finally, we introduce a new technique for detecting pollution attacks. Our technique detects high and low rate attacks on different topologies with high accuracy. (C) 2013 Elsevier B.V. All rights reserved.
引用
收藏
页码:3178 / 3191
页数:14
相关论文
共 50 条
  • [11] Attacks, Detection Mechanisms and Their Limits in Named Data Networking (NDN)
    Hidouri, Abdelhak
    Hadded, Mohamed
    Touati, Haifa
    Hajlaoui, Nasreddine
    Muhlethaler, Paul
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2022, PT I, 2022, 13375 : 310 - 323
  • [12] A Novel Congestion-Aware Interest Flooding Attacks Detection Mechanism in Named Data Networking
    Benmoussa, Ahmed
    Tahari, Abdou el Karim
    Lagraa, Nasreddine
    Lakas, Abderrahmane
    Ahmad, Farhan
    Hussain, Rasheed
    Kerrache, Chaker Abdelaziz
    Kurugollu, Fatih
    2019 28TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2019,
  • [13] On Performance of Cache Policies in Named Data Networking
    Ran, Jianhua
    Lv, Na
    Zhang, Ding
    Ma, Yuanyuan
    Xie, Zhenyong
    PROCEEDINGS OF THE 2013 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER SCIENCE AND ELECTRONICS INFORMATION (ICACSEI 2013), 2013, 41 : 668 - 671
  • [14] Cache Privacy in Named-Data Networking
    Acs, Gergely
    Conti, Mauro
    Gasti, Paolo
    Ghali, Cesar
    Tsudik, Gene
    2013 IEEE 33RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2013, : 41 - 51
  • [15] Investigating Route Cache in Named Data Networking
    Chen, Xin
    Zhang, Guoqiang
    Cui, Huajun
    IEEE COMMUNICATIONS LETTERS, 2018, 22 (02) : 296 - 299
  • [16] Mitigating Cache Pollution Attack Using Deep Learning in Named Data Networking (NDN)
    Hamdi, Mohd Maizan Fishol
    Chen, Zhiyuan
    Radenkovic, Milena
    INTELLIGENT COMPUTING, VOL 2, 2024, 2024, 1017 : 432 - 442
  • [17] Cooperative detection and protection for Interest flooding attacks in named data networking
    Ding, Kun
    Liu, Yun
    Cho, Hsin-Hung
    Chao, Han-Chieh
    Shih, Timothy K.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (13) : 1968 - 1980
  • [18] A Survey on Security Attacks and Intrusion Detection Mechanisms in Named Data Networking
    Hidouri, Abdelhak
    Hajlaoui, Nasreddine
    Touati, Haifa
    Hadded, Mohamed
    Muhlethaler, Paul
    COMPUTERS, 2022, 11 (12)
  • [19] Cache Freshness in Named Data Networking for the Internet of Things
    Meddeb, Maroua
    Dhraief, Amine
    Belghith, Abdelfettah
    Monteil, Thierry
    Drira, Khalil
    Alahmadi, Saad
    COMPUTER JOURNAL, 2018, 61 (10): : 1496 - 1511
  • [20] Protecting Router Cache Privacy in Named Data Networking
    Gao, Manfei
    Zhu, Xiaoyan
    Su, Yang
    2015 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2015,