DocumentCode :
796966
Title :
Mitigating Denial-of-Service Attacks on the Chord Overlay Network: A Location Hiding Approach
Author :
Srivatsa, Mudhakar ; Liu, Ling
Author_Institution :
IBM T.J. Watson Res. Center, Hawthorne, NY
Volume :
20
Issue :
4
fYear :
2009
fDate :
4/1/2009 12:00:00 AM
Firstpage :
512
Lastpage :
527
Abstract :
Serverless distributed computing has received significant attention from both the industry and the research community. Among the most popular applications are the wide area network file systems, exemplified by CFS, Farsite and OceanStore. These file systems store files on a large collection of untrusted nodes that form an overlay network. They use cryptographic techniques to maintain file confidentiality and integrity from malicious nodes. Unfortunately, cryptographic techniques cannot protect a file holder from a Denial-of-Service (DoS) or a host compromise attack. Hence, most of these distributed file systems are vulnerable to targeted file attacks, wherein an adversary attempts to attack a small (chosen) set of files by attacking the nodes that host them. This paper presents LocationGuard - a location hiding technique for securing overlay file storage systems from targeted file attacks. LocationGuard has three essential components: (i) location key, (ii) routing guard, a secure algorithm that protects accesses to a file in the overlay network given its location key, and (iii) a set of location inference guards. Our experimental results quantify the overhead of employing LocationGuard and demonstrate its effectiveness against DoS attacks, host compromise attacks and various location inference attacks.
Keywords :
data encapsulation; distributed processing; file organisation; security of data; LocationGuard; chord overlay network; cryptographic techniques; denial-of-service attacks mitigation; distributed file systems; file confidentiality; host compromise attack; location hiding technique; location inference attacks; overlay file storage systems; routing guard; serverless distributed computing; wide-area network file systems; Distributed Systems; Network Protocols; Security and Privacy Protection;
fLanguage :
English
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
Publisher :
ieee
ISSN :
1045-9219
Type :
jour
DOI :
10.1109/TPDS.2008.125
Filename :
4564446
Link To Document :
بازگشت