• DocumentCode
    2530091
  • Title

    Efficient Detection of Delay-Constrained Relay Nodes

  • Author

    Coskun, Baris ; Memon, Nasir

  • Author_Institution
    Polytech. Univ., Brooklyn
  • fYear
    2007
  • fDate
    10-14 Dec. 2007
  • Firstpage
    353
  • Lastpage
    362
  • Abstract
    Relay nodes are a potential threat to networks since they are used in many malicious situations like stepping stone attacks, botnet communication, peer-to-peer streaming etc. Quick and accurate detection of relay nodes in a network can significantly improve security policy enforcement. There has been significant work done and novel solutions proposed for the problem of identifying relay flows active within a node in the network. However, these solutions require quadratic number of comparisons in the number of flows. In this paper, a related problem of identifying relay nodes is investigated where a relay node is defined as a node in the network that has an active relay flow. The problem is formulated as a variance estimation problem and a statistical approach is proposed for the solution. The proposed solution requires linear time and space in the number of flows and therefore can be employed in large scale implementations. It can be used on its own to identify relay nodes or as a first step in a scalable relay flow detection solution that performs known quadratic time analysis techniques for relay flow detection only on nodes that have been detected as relay nodes. Experimental results show that the proposed scheme is able to detect relay nodes even in the presence of intentional inter-packet delays and chaff packets introduced by adversaries in order to defeat timing based detection algorithms.
  • Keywords
    peer-to-peer computing; statistical analysis; telecommunication security; active relay flow detection; delay-constrained relay node detection; peer-to-peer network; quadratic time analysis technique; statistical approach; variance estimation problem; Application software; Computer security; Delay; Detection algorithms; Large-scale systems; Peer to peer computing; Performance analysis; Protocols; Relays; Timing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
  • Conference_Location
    Miami Beach, FL
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3060-4
  • Type

    conf

  • DOI
    10.1109/ACSAC.2007.29
  • Filename
    4413002