DocumentCode
658704
Title
"Stacking the Deck" Attack on Software Updates: Solution by Distributed Recommendation of Testers
Author
Alhamed, Khalid ; Silaghi, Marius C. ; Hussien, Ihsan ; Stansifer, Ryan ; Yi Yang
Volume
2
fYear
2013
fDate
17-20 Nov. 2013
Firstpage
293
Lastpage
300
Abstract
The discussed "Stacking the Deck" attack and our solution are relevant only to software controlled by loosely constituted communities. Developers can change their vision and abandon features that are essential for certain users. Moreover, well funded attackers can effectively take control of a project by orchestrating the transfer of the leadership of the developers to people that they control. We propose a mechanism to reduce the level of trust that users are required to have in the maintainers of free and open-source agent software. In fact, with the proposed method, it is sufficient for the user to trust that his constellation of independent testers are safe from attack, even as all testers may be subject to different attacks. Our solution inserts independent intermediaries (testers) between the developers and the end-users. To encourage independence of the testers, essential for the desired security, a distributed recommendation mechanism is employed, suggesting testers for end-users based on preferences of immediate connections, and on the frequency of usage of these testers in her neighborhood. Metrics of success and experiments for identifying promising parameters are reported.
Keywords
distributed processing; program testing; recommender systems; security of data; distributed recommendation; distributed recommendation mechanism; open-source agent software; software updates; stacking the deck attack; Mirrors; Security; Social network services; Software; Stacking; Testing; Vectors; agent; recommendation; security; tester; update;
fLanguage
English
Publisher
ieee
Conference_Titel
Web Intelligence (WI) and Intelligent Agent Technologies (IAT), 2013 IEEE/WIC/ACM International Joint Conferences on
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4799-2902-3
Type
conf
DOI
10.1109/WI-IAT.2013.123
Filename
6690803
Link To Document