SybilGuard: Defending against sybil attacks via social networks

SybilGuard: Defending against sybil attacks via social networks
复制标题

DOI:
10.1145/1151659.1159945
复制
发表时间:
2006-10-01
影响因子:
2.8
通讯作者:
Flaxman, Abraham
Flaxman, Abraham
中科院分区:
计算机科学4区
文献类型:
--
作者:
Yu, Haifeng;Kaminsky, Michael;Flaxman, Abraham

文献摘要

被引文献

相似文献

点对点和其他分散的分布式系统特别容易受到Sybil攻击。在Sybil攻击中,恶意用户获得多个虚假身份,并伪装成系统中多个不同的节点。通过控制系统中的大部分节点,恶意用户能够在拜占庭故障防御等协作任务中将诚实的用户投票淘汰。提出了一种新的限制Sybil攻击的腐败影响的协议SybilGuard。我们的协议基于用户身份之间的“社交网络”,其中两个身份之间的边缘表示人类建立的信任关系。恶意用户可以创建许多身份,但很少建立信任关系。因此,在Sybil节点和诚实节点之间的图形中有一个不成比例的小“切割”。SybilGuard利用此属性限制恶意用户可以创建的身份数量。我们通过分析和实验证明了SybilGuard的有效性。
Peer-to-peer and other decentralized, distributed systems are known to be particularly vulnerable to sybil attacks. In a sybil attack, a malicious user obtains multiple fake identities and pretends to be multiple, distinct nodes in the system. By controlling a large fraction of the nodes in the system, the malicious user is able to "out vote" the honest users in collaborative tasks such as Byzantine failure defenses. This paper presents SybilGuard, a novel protocol for limiting the corruptive influences of sybil attacks. Our protocol is based on the "social network" among user identities, where an edge between two identities indicates a human-established trust relationship. Malicious users can create many identities but few trust relationships. Thus, there is a disproportionately-small "cut" in the graph between the sybil nodes and the honest nodes. SybilGuard exploits this property to bound the number of identities a malicious user can create. We show the effectiveness of SybilGuard both analytically and experimentally.