Detecting Malicious Packet Losses

被引:20
|
作者
Mizrak, Alper T. [1 ]
Savage, Stefan [2 ]
Marzullo, Keith [2 ]
机构
[1] VMware, Palo Alto, CA 94304 USA
[2] Univ Calif San Diego, Dept Comp Sci & Engn, La Jolla, CA 92093 USA
关键词
Internet dependability; intrusion detection and tolerance; distributed systems; reliable networks; malicious routers;
D O I
10.1109/TPDS.2008.70
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, we consider the problem of detecting whether a compromised router is maliciously manipulating its stream of packets. In particular, we are concerned with a simple yet effective attack in which a router selectively drops packets destined for some victim. Unfortunately, it is quite challenging to attribute a missing packet to a malicious action because normal network congestion can produce the same effect. Modern networks routinely drop packets when the load temporarily exceeds their buffering capacities. Previous detection protocols have tried to address this problem with a user-defined threshold: too many dropped packets imply malicious intent. However, this heuristic is fundamentally unsound; setting this threshold is, at best, an art and will certainly create unnecessary false positives or mask highly focused attacks. We have designed, developed, and implemented a compromised router detection protocol that dynamically infers, based on measured traffic rates and buffer sizes, the number of congestive packet losses that will occur. Once the ambiguity from congestion is removed, subsequent packet losses can be attributed to malicious actions. We have tested our protocol in Emulab and have studied its effectiveness in differentiating attacks from legitimate network behavior.
引用
收藏
页码:191 / 206
页数:16
相关论文
共 50 条
  • [1] Network Packet Analysis For Detecting Malicious Insider
    Patil, Dinesh
    Meshram, Bandu
    [J]. 2018 3RD INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2018,
  • [2] Networked Control Under Random and Malicious Packet Losses
    Cetinkaya, Ahmet
    Ishii, Hideaki
    Hayakawa, Tomohisa
    [J]. IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2017, 62 (05) : 2434 - 2449
  • [3] Detecting Malicious Node in Network Using Packet Delivery Ratio
    Tyagi, Sanjay
    Gopal, Girdliar
    Garg, Vikas
    [J]. PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 3313 - 3318
  • [4] Detecting malicious packet drops and misroutings using Header Space Analysis
    Mohammadi, Amir Ahmad
    Kazemian, Peyman
    Pakravan, Mohammad Reza
    [J]. 2016 8TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2016, : 521 - 526
  • [5] Enhanced Stability Analysis for Networked Control Systems Under Random and Malicious Packet Losses
    Cetinkaya, Ahmet
    Ishii, Hideaki
    Hayakawa, Tomohisa
    [J]. 2016 IEEE 55TH CONFERENCE ON DECISION AND CONTROL (CDC), 2016, : 2721 - 2726
  • [6] Detecting Malicious Packet Dropping in the Presence of Collisions and Channel Errors in Wireless Ad hoc Networks
    Hayajneh, Thaier
    Krishnamurthy, Prashant
    Tipper, David
    Kim, Taehoon
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 1062 - 1067
  • [7] Detecting malicious SQL
    Fonseca, Jose
    Vieira, Marco
    Madeira, Henrique
    [J]. TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2007, 4657 : 259 - +
  • [8] Malicious Hubs: Detecting Abnormally Malicious Autonomous Systems
    Kalafut, Andrew J.
    Shue, Craig A.
    Gupta, Minaxi
    [J]. 2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [9] Almost surely state estimation for multi-rate networked systems under random and malicious packet losses
    Zheng, Xiaoyuan
    Zhang, Hao
    Wang, Zhuping
    Yan, Huaicheng
    [J]. JOURNAL OF THE FRANKLIN INSTITUTE-ENGINEERING AND APPLIED MATHEMATICS, 2019, 356 (17): : 10593 - 10607
  • [10] Characterizing and Detecting Malicious Crowdsourcing
    Wang, Tianyi
    Wang, Gang
    Li, Xing
    Zheng, Haito
    Zhao, Ben Y.
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2013, 43 (04) : 537 - 538