Magic Train: Design of Measurement Methods against Bandwidth Inflation Attacks

被引:2
作者
Zhou, Peng [1 ]
Chang, Rocky K. C. [2 ]
Gu, Xiaojing [3 ]
Fei, Minrui [1 ]
Zhou, Jianying [4 ]
机构
[1] Shanghai Univ, Sch Mechatron Engn & Automat, Shanghai 200072, Peoples R China
[2] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[3] East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai 200237, Peoples R China
[4] Inst Infocomm Res, Singapore 138632, Singapore
基金
中国国家自然科学基金;
关键词
Network measurement; network security; packet train; NETWORKS; PERFORMANCE; SYSTEM; SPEED;
D O I
10.1109/TDSC.2015.2509984
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Bandwidth measurement is important for many network applications and services, such as peer-to-peer networks, video caching and anonymity services. To win a bandwidth-based competition for some malicious purpose, adversarial Internet hosts may falsely announce a larger network bandwidth. Some preliminary solutions have been proposed to this problem. They can either evade the bandwidth inflation by a consensus view (i.e., opportunistic bandwidth measurements) or detect bandwidth frauds via forgeable tricks (i.e., detection through bandwidth's CDF symmetry). However, smart adversaries can easily remove the forgeable tricks and report an equally larger bandwidth to avoid the consensus analyses. To defend against the smart bandwidth inflation frauds, we design magic train, a new measurement method which combines an unpredictable packet train with estimated round-trip time (RTT) for detection. The inflation behaviors can be detected through highly contradictory bandwidth results calculated using different magic trains or a train's different segments, or large deviation between the estimated RTT and the RTT reported by the train's first packet. Being an uncooperative measurement method, magic train can be easily deployed on the Internet. We have implemented the magic train using RAW socket and LibPcap, and evaluated the implementation in a controlled testbed and the Internet. The results have successfully confirmed the effectiveness of magic train in detecting and preventing smart bandwidth inflation attacks.
引用
收藏
页码:98 / 111
页数:14
相关论文
共 51 条
  • [1] [Anonymous], 2004, P 13 C USENIX SEC S, DOI [DOI 10.5555/1251375.1251396, DOI 10.1186/1476-0711-3-21]
  • [2] [Anonymous], 2013, G992 5 ASYMMETRIC DI
  • [3] [Anonymous], 2012, Linux Programmer's Manual: numa(7) - overview of Non-Uniform Memory Architecture
  • [4] [Anonymous], 2013, THE LIBPCAP PROJECT
  • [5] Measuring Multipath Routing in the Internet
    Augustin, Brice
    Friedman, Timur
    Teixeira, Renata
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2011, 19 (03) : 830 - 840
  • [6] Avramopoulos I., 2006, ATEC 06 P ANN C USEN, P25
  • [7] Avramopoulos I., 2006, SECURE DATA DELIVERY
  • [8] Bauer K, 2007, WPES'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON PRIVACY IN ELECTRONIC SOCIETY, P11
  • [9] Beizer B., 1995, BLACK BOX TESTING TE
  • [10] Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization
    Biryukov, Alex
    Pustogarov, Ivan
    Weinmann, Ralf-Philipp
    [J]. 2013 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2013, : 80 - 94