Measurement Integrity Attacks Against Network Tomography: Feasibility and Defense
Measurement Integrity Attacks Against Network Tomography: Feasibility and Defense
复制标题
DOI:
10.1109/tdsc.2019.2958934
复制
发表时间:
2021-11
影响因子:
7.3
通讯作者:
Shangqing Zhao;Zhuo Lu;Cliff X. Wang
中科院分区:
文献类型:
--
作者:
Shangqing Zhao;Zhuo Lu;Cliff X. Wang
Network tomography is an important tool to estimate link metrics from end-to-end network measurements. An implicit assumption in network tomography is that observed measurements indeed reflect the aggregate of link performance (i.e., seeing is believing). However, it is not guaranteed today that there exists no anomaly (e.g., malicious autonomous systems and insider threats) in large-scale networks. Malicious nodes can intentionally manipulate link metrics via delaying or dropping packets to affect measurements. Will such an assumption render a vulnerability when facing attackers? The problem is of essential importance in that network tomography is developed towards effective network diagnostics and failure recovery. In this article, we demonstrate that the vulnerability is real and propose a new attack strategy, called measurement integrity attack, in which malicious nodes can substantially damage a network (e.g., delaying packets) and at the same time maliciously manipulate end-to-end measurement results such that a legitimate node is misleadingly identified as the root cause of the damage (thereby becoming a scapegoat) under network tomography. We formulate three basic attack approaches and show under what conditions attacks can be successful. We also reveal conditions to detect and locate such attacks in a network. Our theoretical and experimental results show that simply trusting measurements leads to measurement integrity vulnerabilities. Thus, existing methods should be revisited accordingly for security in various applications.