首页> 外文会议>IEEE Conference on Computer Communications Workshops >Mitigating poisoned content with forwarding strategy
【24h】

Mitigating poisoned content with forwarding strategy

机译:通过转发策略缓解中毒内容

获取原文

摘要

Content poisoning attacks are a significant problem in Information Centric Networks (ICN), such as Named Data Networking. In a content poisoning attack, an attacker injects bogus content into the network with a legitimate name. While users will reject the content because of signature mismatch, the network is largely unaware of the problem due to the computational burden of on the fly packet verification. Thus, subsequent requests may continued to be answered by bogus content and constitute a denial of service attack. While NDN could resist poisoned content by putting restrictions on prefix advertisement, the latter interferes with the “content from anywhere” principle, which we consider to be a great advantage of NDN. This work explores the problem of content poisoning in depth and surveys the state of the art in mitigation mechanisms. We then present a novel system for detecting, reporting, and avoiding poisoned content that leverages the verification work that users must do anyways. We also propose the use of evasion strategies: pre-processor modules that assist forwarding strategy in avoiding bad content sources. We evaluate two evasion strategies, Immediate Failover and Probe First, that capture the spectrum of possible solutions to avoiding bad content.
机译:内容中毒攻击是诸如命名数据网络之类的信息中心网络(ICN)中的一个重要问题。在内容中毒攻击中,攻击者使用合法名称将虚假内容注入网络。尽管用户将由于签名不匹配而拒绝内容,但是由于动态数据包验证的计算负担,网络在很大程度上没有意识到这一问题。因此,后续请求可能会继续由虚假内容回答,并构成拒绝服务攻击。尽管NDN可以通过限制前缀广告来抵制中毒内容,但后者会干扰“无处不在的内容”原则,我们认为这是NDN的一大优势。这项工作深入探讨了内容中毒的问题,并研究了缓解机制中的最新技术。然后,我们提出了一种新颖的系统,用于检测,报告和避免中毒的内容,该系统利用了用户无论如何都必须执行的验证工作。我们还建议使用规避策略:协助转发策略避免不良内容来源的预处理器模块。我们评估了两种规避策略,即立即故障转移和探查优先,它们捕获了各种可能的解决方案以避免不良内容。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号