Measurement Integrity Attacks Against Network Tomography: Feasibility and Defense

Measurement Integrity Attacks Against Network Tomography: Feasibility and Defense
复制标题

DOI:
10.1109/tdsc.2019.2958934
复制
发表时间:
2021-11
影响因子:
7.3
通讯作者:
Shangqing Zhao;Zhuo Lu;Cliff X. Wang
Shangqing Zhao;Zhuo Lu;Cliff X. Wang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Shangqing Zhao;Zhuo Lu;Cliff X. Wang

文献摘要

相似文献

网络断层扫描是一种重要的工具,估计链路度量从端到端的网络测量。网络层析成像中的隐含假设是观察到的测量确实反映了链路性能的集合(即,眼见为实)。然而,目前不能保证不存在异常(例如,恶意自治系统和内部威胁)。恶意节点可以通过延迟或丢弃数据包来故意操纵链路度量以影响测量。这样的假设在面对攻击者时会造成漏洞吗?这个问题是至关重要的,网络断层扫描是朝着有效的网络诊断和故障恢复。在这篇文章中,我们证明了漏洞是真实的,并提出了一种新的攻击策略,称为测量完整性攻击,其中恶意节点可以实质性地破坏网络(例如,延迟分组),同时恶意地操纵端到端测量结果,使得在网络断层扫描下,合法节点被误导性地识别为损坏的根本原因(从而成为替罪羊)。我们制定了三个基本的攻击方法,并显示在什么条件下攻击可以成功。我们还揭示了在网络中检测和定位此类攻击的条件。我们的理论和实验结果表明,简单地信任测量会导致测量完整性漏洞。因此,现有的方法应相应地重新审查各种应用程序中的安全性。
Network tomography is an important tool to estimate link metrics from end-to-end network measurements. An implicit assumption in network tomography is that observed measurements indeed reflect the aggregate of link performance (i.e., seeing is believing). However, it is not guaranteed today that there exists no anomaly (e.g., malicious autonomous systems and insider threats) in large-scale networks. Malicious nodes can intentionally manipulate link metrics via delaying or dropping packets to affect measurements. Will such an assumption render a vulnerability when facing attackers? The problem is of essential importance in that network tomography is developed towards effective network diagnostics and failure recovery. In this article, we demonstrate that the vulnerability is real and propose a new attack strategy, called measurement integrity attack, in which malicious nodes can substantially damage a network (e.g., delaying packets) and at the same time maliciously manipulate end-to-end measurement results such that a legitimate node is misleadingly identified as the root cause of the damage (thereby becoming a scapegoat) under network tomography. We formulate three basic attack approaches and show under what conditions attacks can be successful. We also reveal conditions to detect and locate such attacks in a network. Our theoretical and experimental results show that simply trusting measurements leads to measurement integrity vulnerabilities. Thus, existing methods should be revisited accordingly for security in various applications.