DocumentCode
2300132
Title
Behavioral Detection and Containment of Proximity Malware in Delay Tolerant Networks
Author
Peng, Wei ; Li, Feng ; Zou, Xukai ; Wu, Jie
Author_Institution
Dept. of Comput. & Inf. Sci., Indiana Univ.-Purdue Univ., Indianapolis, IN, USA
fYear
2011
fDate
17-22 Oct. 2011
Firstpage
411
Lastpage
420
Abstract
With the universal presence of short-range connectivity technologies (e.g., Bluetooth and, more recently, Wi-Fi Direct) in the consumer electronics market, the delay-tolerant-network (DTN) model is becoming a viable alternative to the traditional infrastructural model. Proximity malware, which exploits the temporal dimension and distributed nature of DTNs in self-propagation, poses threats to users of new technologies. In this paper, we address the proximity malware detection and containment problem with explicit consideration for the unique characteristics of DTNs. We formulate the malware detection process as a decision problem under a general behavioral malware characterization framework. We analyze the risk associated with the decision problem and design a simple yet effective malware containment strategy, look-ahead, which is distributed by nature and reflects an individual node´s intrinsic trade-off between staying connected (with other nodes) and staying safe (from malware). Furthermore, we consider the benefits of sharing assessments among directly connected nodes and address the challenges derived from the DTN model to such sharing in the presence of liars (i.e., malicious nodes sharing false assessments) and defectors (i.e., good nodes that have turned malicious due to malware infection). Real mobile network traces are used to verify our analysis.
Keywords
invasive software; mobile radio; telecommunication security; DTN model; delay tolerant networks; general behavioral malware characterization framework; infrastructural model; mobile network; proximity malware containment detection; short-range connectivity technology; Computers; Equations; Malware; Mobile computing; Peer to peer computing; Robustness; Silicon; ?- robustness; delay-tolerant networks (DTNs); dogmatism d; look-ahead ?; malware behav- ioral characterization; proximity malware;
fLanguage
English
Publisher
ieee
Conference_Titel
Mobile Adhoc and Sensor Systems (MASS), 2011 IEEE 8th International Conference on
Conference_Location
Valencia
ISSN
2155-6806
Print_ISBN
978-1-4577-1345-3
Type
conf
DOI
10.1109/MASS.2011.48
Filename
6076639
Link To Document