Defense against pollution attacks in network coding

Athina P. Markopoulou, Anh Le · 2012

Network coding is a paradigm that advocates that intermediate nodes are allowed to combine, in addition to forward, packets. This idea has generated a significant amount of attention in the research community and has been shown to improve throughput and robustness. However, network coding is particularly vulnerable to pollution attacks, where corrupted packets injected by attackers may cause significant degradation of network performance. If network coding is to succeed, it has to overcome pollution attacks. As a result, there is a large body of work, in both the communications and applied cryptography communities, that proposes defense schemes for network coded systems against pollution attacks. In this thesis, we combat pollution attacks in both intra and inter-session coding, using cryptographic primitives. In particular, we present two efficient, comprehensive defense schemes for intra-session coding: one for directed acyclic networks that have fixed topologies and one for general networks that have dynamic topologies. Both of these schemes can provide in-network attack detection as well as precise identification of the location of attackers. They are built on a novel homomorphic message authentication code (MAC) scheme called SpaceMac. To the best of our knowledge, SpaceMac is the first homomorphic MAC scheme which allows for authenticating a subspace that expands over time. We implemented SpaceMac in both Java and C++ as a library and made the source code publicly available. In addition, we present an efficient in-network attack detection scheme for inter-session coding. The detection scheme is built on a novel multi-source homomorphic MAC scheme called InterMac. To the best of our knowledge, InterMac is the first homomorphic MAC scheme that allows tags to be generated under multiple, different keys. Finally, we propose a data auditing scheme called NC-Audit for network coding storage. NC-Audit is built on SpaceMac and on a novel chosen-plaintext-secure encryption scheme for network coding called NCrypt. NC-Audit exploits the similarity between pollution detection and data integrity checking to provide an efficient, privacy-preserving integrity checking, as well as support for efficient data repair and data dynamics.

Read the paper · More papers on PaperTik