Please use this identifier to cite or link to this item:
http://dspace.cityu.edu.hk/handle/2031/8671
Title: | PMFA: toward passive message fingerprint attacks on challenge-based collaborative intrusion detection networks |
Authors: | Li, Wenjuan Kwok, L. F. Ip, H. Meng, W. |
Department: | Department of Computer Science |
Issue Date: | Sep-2016 |
Award: | Won the Best Student Paper Award in the 10th International Conference on Network and System Security (NSS 2016) held in Taipei, Taiwan on 28-30 September 2016. |
Supervisor: | Dr. Kwok, L. F.; Prof. Ip, Horace |
Type: | Conference paper/presentation |
Abstract: | To enhance the performance of single intrusion detection systems (IDSs), collaborative intrusion detection networks (CIDNs) have been developed, which enable a set of IDS nodes to communicate with each other. In such a distributed network, insider attacks like collusion attacks are the main threat. In the literature, challenge-based trust mechanisms have been established to identify malicious nodes by evaluating the satisfaction between challenges and responses. However, we find that such mechanisms rely on two major assumptions, which may result in a weak threat model and make CIDNs still vulnerable to advanced insider attacks in practical deployment. In this paper, we design a novel type of collusion attack, called passive message fingerprint attack (PMFA), which can collect messages and identify normal requests in a passive way. In the evaluation, we explore the attack performance under both simulated and real network environments. Experimental results indicate that under our attack, malicious nodes can send malicious responses to normal requests while maintaining their trust values. |
Appears in Collections: | Student Works With External Awards |
Files in This Item:
There are no files associated with this item.
Items in Digital CityU Collections are protected by copyright, with all rights reserved, unless otherwise indicated.