首页> 外文会议>IFIP International Conference on New Technologies, Mobility and Security >A Detection and Defense Approach for Content Privacy in Named Data Network
【24h】

A Detection and Defense Approach for Content Privacy in Named Data Network

机译:命名数据网络中内容隐私的检测与防御方法

获取原文

摘要

The Named Data Network (NDN) is a promising network paradigm for content distribution based on caching. However, it may put consumer privacy at risk, as the adversary may identify the content, the name and the signature (namely a certificate) through side-channel timing responses from the cache of the routers. The adversary may identify the content name and the consumer node by distinguishing between cached and un- cached contents. In order to mitigate the timing attack, effective countermeasure methods have been proposed by other authors, such as random caching, random freshness, and probabilistic caching. In this work, we have implemented a timing attack scenario to evaluate the efficiency of these countermeasures and to demonstrate how the adversary can be detected. For this goal, a brute force timing attack scenario based on a real topology was developed, which is the first brute force attack model applied in NDN. Results show that the adversary nodes can be effectively distinguished from other legitimate consumers during the attack period. It is also proposed a multi-level mechanism to detect an adversary node. Through this approach, the content distribution performance can be mitigated against the attack.
机译:命名数据网络(NDN)是用于基于缓存的内容分发的有前途的网络范例。但是,这可能会使消费者的隐私受到威胁,因为攻击者可能会通过来自路由器缓存的侧信道定时响应来识别内容,名称和签名(即证书)。对手可以通过区分缓存的内容和未缓存的内容来标识内容名称和消费者节点。为了减轻定时攻击,其他作者提出了有效的对策方法,例如随机缓存,随机新鲜度和概率缓存。在这项工作中,我们实施了定时攻击方案,以评估这些对策的效率并演示如何检测到对手。为此,开发了基于真实拓扑的暴力定时攻击场景,这是NDN中第一个应用的暴力攻击模型。结果表明,在攻击期间可以有效地将对手节点与其他合法消费者区分开。还提出了一种用于检测对手节点的多级机制。通过这种方法,可以降低内容分发性能以抵御攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号