Distributed Social Platforms for Confidentiality and Resilience

Distributed Social Platforms for Confidentiality and Resilience
复制标题

具有保密性和弹性的分布式社交平台

DOI:
10.4018/978-1-4666-3926-3.ch006
复制
发表时间:
2013
期刊:
--
影响因子:
--
通讯作者:
M. Tomaiuolo
M. Tomaiuolo
中科院分区:
--
文献类型:
--
作者:
E. Franchi;M. Tomaiuolo

文献摘要

参考文献

被引文献

相似文献

在过去的几年里,社交网站已经深刻地改变了人们对网络的看法。尽管当前构建社交网络系统的方法是创建由单个公司拥有的巨大集中式系统,但是这种策略具有许多缺点,例如,缺乏隐私,缺乏匿名性,审查的风险和运营成本。这些问题与信息系统的一些主要要求形成对照,其中包括:用户与系统之间的互动必须保密,除非明确公开; ㈡完整性; ㈢问责制; ㈣可用性; ㈤身份和匿名。此外,社交网络平台容易受到许多类型的攻击:(i)伪装,当用户伪装他的身份并假装是另一个用户时发生;(ii)未经授权的访问;(iii)拒绝服务;(iv)否认,当用户参与活动并后来声称他没有参与时发生;(v)窃听;(vi)更改数据;(vii)复制和重放攻击;(vi)攻击;(以及,一般来说,(viii)利用社会工程技术的攻击。为了克服集中式系统的固有缺陷和社交网络平台的一般脆弱性,已经提出了许多不同的方法,无论是作为联合(即,由合作提供服务的多个实体组成,但通常与用户不同)或对等系统(用户直接合作提供服务);在这项工作中,我们回顾了最有趣的系统。最后,我们提出了自己的方法来创建一个坚实的分布式社交网络平台,包括一个新的点对点系统,利用现有的,广泛的和稳定的技术,如分布式哈希表和BitTorrent。我们主要关注的主题是:(一)匿名性和对审查的弹性;(二)可认证的内容;(三)使用活动流和弱语义数据格式的联系人和个人资料的语义互操作性;以及(四)数据可用性。
Social networking sites have deeply changed the perception of the web in the last years. Although the current approach to build social networking systems is to create huge centralized systems owned by a single company, such strategy has many drawbacks, e.g., lack of privacy, lack of anonymity, risks of censorship and operating costs. These issues contrast with some of the main requirements of information systems, including: (i) confidentiality, i.e., the interactions between a user and the system must remain private unless explicitly public; (ii) integrity; (iii) accountability; (iv) availability; (v) identity and anonymity. Moreover, social networking platforms are vulnerable to many kind of attacks: (i) masquerading, which occurs when a user disguises his identity and pretends to be another user; (ii) unauthorized access; (iii) denial of service; (iv) repudiation, which occurs when a user participates in an activity and later claims he did not; (v) eavesdropping; (vi) alteration of data; (vii) copy and replay attacks; and, in general, (viii) attacks making use of social engineering techniques. In order to overcome both the intrinsic defects of centralized systems and the general vulnerabilities of social networking platforms, many different approaches have been proposed, both as federated (i.e., consisting of multiple entities cooperating to provide the service, but usually distinct from users) or peer-to-peer systems (with users directly cooperating to provide the service); in this work we reviewed the most interesting ones. Eventually, we present our own approach to create a solid distributed social networking platform consisting in a novel peer-to-peer system that leverages existing, widespread and stable technologies such as distributed hash tables and BitTorrent. The topics we are mainly concerned with are: (i) anonymity and resilience to censorship; (ii) authenticatable contents; (iii) semantic interoperability using activity streams and weak semantic data formats for contacts and profiles; and (iv) data availability.
DOI: --
发表时间: 2006
期刊: Journal of IEICE Vol.89, No.2
影响因子: --
作者:
Taku Noguchi;Miki Yamamoto
通讯作者: Miki Yamamoto