An ANFIS-based cache replacement method for mitigating cache pollution attacks in Named Data Networking

An ANFIS-based cache replacement method for mitigating cache pollution attacks in Named Data Networking
复制标题

DOI:
10.1016/j.comnet.2015.01.020
复制
发表时间:
2015-04
期刊:
Comput. Networks
影响因子:
--
通讯作者:
Amin Karami;Manel Guerrero Zapata
Amin Karami;Manel Guerrero Zapata
中科院分区:
其他
文献类型:
--
作者:
Amin Karami;Manel Guerrero Zapata

文献摘要

被引文献

相似文献

命名数据网络(NDN)是一个候选的下一代互联网架构,旨在克服目前基于IP的互联网的基本限制,特别是强大的安全性。无处不在的网络缓存是NDN的一个关键特性。然而,普适高速缓存强化了安全问题,即包括高速缓存中毒(即,将恶意内容作为假局部性引入高速缓存)和高速缓存污染(即,针对NDN中该高速缓存污染攻击,提出了一种基于自适应神经模糊推理系统(ANFIS)的缓存替换方法。ANFIS结构是使用与缓存内容的固有特性相关的输入数据和与内容类型相关的输出(即,健康、局部破坏和假局部)。所提出的方法检测假本地和本地中断攻击,以及两者的组合在不同的拓扑结构具有高精度,并有效地减轻他们没有太多的计算成本相比,最常见的政策。
Named Data Networking (NDN) is a candidate next-generation Internet architecture designed to overcome the fundamental limitations of the current IP-based Internet, in particular strong security. The ubiquitous in-network caching is a key NDN feature. However, pervasive caching strengthens security problems namely cache pollution attacks including cache poisoning (i.e., introducing malicious content into caches as false-locality) and cache pollution (i.e., ruining the cache locality with new unpopular content as locality-disruption).In this paper, a new cache replacement method based on Adaptive Neuro-Fuzzy Inference System (ANFIS) is presented to mitigate the cache pollution attacks in NDN. The ANFIS structure is built using the input data related to the inherent characteristics of the cached content and the output related to the content type (i.e., healthy, locality-disruption, and false-locality). The proposed method detects both false-locality and locality-disruption attacks as well as a combination of the two on different topologies with high accuracy, and mitigates them efficiently without very much computational cost as compared to the most common policies.