• DocumentCode
    2300132
  • Title

    Behavioral Detection and Containment of Proximity Malware in Delay Tolerant Networks

  • Author

    Peng, Wei ; Li, Feng ; Zou, Xukai ; Wu, Jie

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Indiana Univ.-Purdue Univ., Indianapolis, IN, USA
  • fYear
    2011
  • fDate
    17-22 Oct. 2011
  • Firstpage
    411
  • Lastpage
    420
  • Abstract
    With the universal presence of short-range connectivity technologies (e.g., Bluetooth and, more recently, Wi-Fi Direct) in the consumer electronics market, the delay-tolerant-network (DTN) model is becoming a viable alternative to the traditional infrastructural model. Proximity malware, which exploits the temporal dimension and distributed nature of DTNs in self-propagation, poses threats to users of new technologies. In this paper, we address the proximity malware detection and containment problem with explicit consideration for the unique characteristics of DTNs. We formulate the malware detection process as a decision problem under a general behavioral malware characterization framework. We analyze the risk associated with the decision problem and design a simple yet effective malware containment strategy, look-ahead, which is distributed by nature and reflects an individual node´s intrinsic trade-off between staying connected (with other nodes) and staying safe (from malware). Furthermore, we consider the benefits of sharing assessments among directly connected nodes and address the challenges derived from the DTN model to such sharing in the presence of liars (i.e., malicious nodes sharing false assessments) and defectors (i.e., good nodes that have turned malicious due to malware infection). Real mobile network traces are used to verify our analysis.
  • Keywords
    invasive software; mobile radio; telecommunication security; DTN model; delay tolerant networks; general behavioral malware characterization framework; infrastructural model; mobile network; proximity malware containment detection; short-range connectivity technology; Computers; Equations; Malware; Mobile computing; Peer to peer computing; Robustness; Silicon; ?- robustness; delay-tolerant networks (DTNs); dogmatism d; look-ahead ?; malware behav- ioral characterization; proximity malware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Mobile Adhoc and Sensor Systems (MASS), 2011 IEEE 8th International Conference on
  • Conference_Location
    Valencia
  • ISSN
    2155-6806
  • Print_ISBN
    978-1-4577-1345-3
  • Type

    conf

  • DOI
    10.1109/MASS.2011.48
  • Filename
    6076639