2006 · 312 citations · 40 references
EngineeringInformation SecurityInformation ForensicsFormal VerificationDos AttacksDistributed Source CodingSecure ComputingSecure ProtocolNetwork SecurityData PrivacyComputer ScienceCooperative SecurityData SecurityCryptographyCloud ComputingPeer-to-peer DatabaseLinear Network CodingNetwork CodingTrusted P2pBlockchainPractical Security Scheme
Peer‑to‑peer content distribution networks that use network coding are vulnerable to malicious participants, as traditional cryptographic signatures and hashes are ill‑suited for these schemes and detecting corrupted blocks requires costly homomorphic hashing, leading to potential jamming attacks that propagate many bad blocks. This work proposes a practical, low‑cost on‑the‑fly block verification scheme for network coding that efficiently prevents malicious block propagation. The scheme relies on cooperative users who, upon detecting a malicious block, notify affected nodes, and incorporates analytical techniques to mitigate denial‑of‑service attacks. Experiments show that limiting verification to 1–5 % of received blocks keeps corruption rates low, and the system’s efficiency loss is bounded by the attackers’ effort, establishing a natural lower bound on damage.
Peer-to-peer content distribution networks can suffer from malicious participants that corrupt content. Current systems verify blocks with traditional cryptographic signatures and hashes. However, these techniques do not apply well to more elegant schemes that use network coding techniques for efficient content distribution. Architectures that use network coding are prone to jamming attacks where the introduction of a few corrupted blocks can quickly result in a large number of bad blocks propagating through the system. Identifying such bogus blocks is difficult and requires the use of homomorphic hashing functions, which are computationally expensive. This paper presents a practical security scheme for network coding that reduces the cost of verifying blocks on-the-fly while efficiently preventing the propagation of malicious blocks. In our scheme, users not only cooperate to distribute the content, but (well-behaved) users also cooperate to protect themselves against malicious users by informing affected nodes when a malicious block is found. We analyze and study such cooperative security scheme and introduce elegant techniques to prevent DoS attacks. We show that the loss in the efficiency caused by the attackers is limited to the effort the attackers put to corrupt the communication, which is a natural lower bound in the damage of the system. We also show experimentally that checking as low as 1-5% of the received blocks is enough to guarantee low corruption rates.
40
Rudolf Ahlswede, Ning Cai, Shuo Li et al. · IEEE Transactions on Information Theory · 2000 · 7.8K citations
Incentives Build Robustness in Bit-Torrent
Bram Cohen · 2003 · 2.7K citations
Eytan Adar, Bernardo A. Huberman · First Monday · 2000 · 1.5K citations · Full text
User Traffic, Computational Social Science, Distributed Search Engine +15
How Practical is Network Coding?
Mea Wang, Baochun Li · International Workshop on Quality of Service · 2006 · 1.4K citations