Collusion Attack Detection in Networked Systems
Md Zakirul Alam Bhuiyan, Jie Wu · 2016
Security protocols have been commonly used to protect secure communication in networked systems. It is often assumed that individual wireless nodes or leaders in a system are sincere and use techniques (authentication, permission, etc.) of these protocols to have secure communications. We discover that such protocols may be leaked by a sophisticated collusion attack (a type of attacks in which a node intentionally has a secret agreement with an adversary, or is compromised by an adversary). Before an attack is made, the node seems to be working properly, communicating with others, and providing correct values/decisions. Currently, there is no systematic method for detecting such an attack. In this paper, we propose CAD, a Collusion Attack Detection scheme for networked systems. We think that wireless nodes usually have some correlation patterns in communication metrics (e.g., radio timing, amount of packets transmitted). When there is a significant discrepancy in such patterns with a node, the node is said to be colluded. We evaluate CAD in simulations with real data traces. Evaluation results demonstrate that CAD achieves a collusion detection rate up to 92%, which is at least 50% better compared to existing schemes.