Exploiting Temporal Dynamics in Sybil Defenses

Exploiting Temporal Dynamics in Sybil Defenses
复制标题

在女巫防御中利用时间动力学

DOI:
10.1145/2810103.2813693
复制
发表时间:
2015
期刊:
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Mittal, Prateek
Mittal, Prateek
中科院分区:
--
文献类型:
--
作者:
Liu, Changchang;Gao, Peng;Wright, Matthew;Mittal, Prateek

文献摘要

参考文献

被引文献

相似文献

Sybil攻击对许多互联网系统和应用程序构成了重大威胁,其中单个攻击者在系统中插入多个合谋身份,以危及其安全性和隐私。最近的工作提倡使用基于社交网络的信任关系来防御Sybil攻击。然而,大多数此类系统的先前安全分析仅检查单个时刻的社交网络的情况。在实践中,社交网络连接会随着时间的推移而变化,攻击者也可以对网络造成有限的变化。在这项工作中,我们专注于各种基于社会网络的Sybil防御的时间动态。我们描述和研究的影响,新的攻击的基础上:(a)攻击者的能力,修改Sybil控制的部分的社会网络图,(B)他的能力,以改变连接,他的Sybil身份保持诚实的用户,和(c)利用定期动态的连接形成和打破诚实的一部分的社会网络。我们发现,对一些防御意味着是完全分布式的,如SybilLimit和Persea,攻击者可以取得显着的收益随着时间的推移,大大破坏了系统的安全保证。即使针对集中控制的Sybil防御,攻击者最终也可以逃避检测(例如针对SybilInfer和SybilRank)或创建拒绝服务条件(例如针对Ostra和SumUp)。在使用合成和真实世界的社交网络拓扑结构对这些攻击进行分析和模拟之后,我们描述了可能的防御策略和应该探索的权衡。从我们的研究结果中可以清楚地看出,在Sybil防御中需要考虑时间动态,否则攻击者将能够以意想不到的和可能危险的方式破坏系统。
Sybil attacks present a significant threat to many Internet systems and applications, in which a single adversary inserts multiple colluding identities in the system to compromise its security and privacy. Recent work has advocated the use of social-network-based trust relationships to defend against Sybil attacks. However, most of the prior security analyses of such systems examine only the case of social networks at a single instant in time. In practice, social network connections change over time, and attackers can also cause limited changes to the networks. In this work, we focus on the temporal dynamics of a variety of social-network-based Sybil defenses. We describe and examine the effect of novel attacks based on: (a) the attacker's ability to modify Sybil-controlled parts of the social-network graph, (b) his ability to change the connections that his Sybil identities maintain to honest users, and (c) taking advantage of the regular dynamics of connections forming and breaking in the honest part of the social network. We find that against some defenses meant to be fully distributed, such as SybilLimit and Persea, the attacker can make dramatic gains over time and greatly undermine the security guarantees of the system. Even against centrally controlled Sybil defenses, the attacker can eventually evade detection (e.g. against SybilInfer and SybilRank) or create denial-of-service conditions (e.g. against Ostra and SumUp). After analysis and simulation of these attacks using both synthetic and real-world social network topologies, we describe possible defense strategies and the trade-offs that should be explored. It is clear from our findings that temporal dynamics need to be accounted for in Sybil defense or else the attacker will be able to undermine the system in unexpected and possibly dangerous ways.
遏制对电话验证帐户的滥用行为
DOI: --
发表时间: 2014
期刊: Conference on Computer and Communications Security
影响因子: --
作者:
Kurt Thomas;D. Iatskiv;Elie Bursztein;Tadek Pietraszek;Chris Grier;Damon McCoy
通讯作者: Damon McCoy