Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking

Named data networking (NDN) has emerged as a future networking architecture having the potential to replace the Internet. In order to do so, the NDN needs to cope with inherent problems of the Internet, such as attacks that cause information leakage from an enterprise. Since NDN has not yet been dep...

Full description

Bibliographic Details
Main Authors: Daishi Kondo, Thomas Silverston, Vassilis Vassiliades, Hideki Tode, Tohru Asami
Format: Article
Language:English
Published: IEEE 2018-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8506363/
_version_ 1818331824688988160
author Daishi Kondo
Thomas Silverston
Vassilis Vassiliades
Hideki Tode
Tohru Asami
author_facet Daishi Kondo
Thomas Silverston
Vassilis Vassiliades
Hideki Tode
Tohru Asami
author_sort Daishi Kondo
collection DOAJ
description Named data networking (NDN) has emerged as a future networking architecture having the potential to replace the Internet. In order to do so, the NDN needs to cope with inherent problems of the Internet, such as attacks that cause information leakage from an enterprise. Since NDN has not yet been deployed on a large scale, it is currently unknown how such attacks can occur, let alone what countermeasures can be taken against them. In this paper, we first show that information leakage in NDN can be caused by malware inside an enterprise, which uses steganography to produce malicious interest names encoding confidential information. We investigate such attacks by utilizing a content name dataset based on uniform resource locators (URLs) collected by a Web crawler. Our main contribution is a name filter based on anomaly detection that takes the dataset as input and classifies a name in the Interest as legitimate or not. Our evaluation shows that the malware can exploit the path part in the URL-based NDN name to create malicious names, thus, information leakage in the NDN cannot be prevented completely. However, we show for the first time that our filter can dramatically choke the leakage throughput causing the malware to be 137 times less efficient at leaking information. This finding opens up an interesting avenue of research that could result in a safer future networking architecture.
first_indexed 2024-12-13T13:25:59Z
format Article
id doaj.art-0c7fa257c7a44cf78abcb6d1cd7892d0
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-13T13:25:59Z
publishDate 2018-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-0c7fa257c7a44cf78abcb6d1cd7892d02022-12-21T23:44:17ZengIEEEIEEE Access2169-35362018-01-016651516517010.1109/ACCESS.2018.28777928506363Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data NetworkingDaishi Kondo0https://orcid.org/0000-0003-1482-6148Thomas Silverston1Vassilis Vassiliades2Hideki Tode3Tohru Asami4University of Lorraine, LORIA, CNRS UMR 7503, Vandoeuvre-les-Nancy, FranceShibaura Institute of Technology, Tokyo, JapanDepartment of Computer Science, University of Cyprus, Nicosia, CyprusDepartment of Computer Science and Intelligent Systems, Osaka Prefecture University, Sakai, JapanAdvanced Telecommunications Research Institute International, Kyoto, JapanNamed data networking (NDN) has emerged as a future networking architecture having the potential to replace the Internet. In order to do so, the NDN needs to cope with inherent problems of the Internet, such as attacks that cause information leakage from an enterprise. Since NDN has not yet been deployed on a large scale, it is currently unknown how such attacks can occur, let alone what countermeasures can be taken against them. In this paper, we first show that information leakage in NDN can be caused by malware inside an enterprise, which uses steganography to produce malicious interest names encoding confidential information. We investigate such attacks by utilizing a content name dataset based on uniform resource locators (URLs) collected by a Web crawler. Our main contribution is a name filter based on anomaly detection that takes the dataset as input and classifies a name in the Interest as legitimate or not. Our evaluation shows that the malware can exploit the path part in the URL-based NDN name to create malicious names, thus, information leakage in the NDN cannot be prevented completely. However, we show for the first time that our filter can dramatically choke the leakage throughput causing the malware to be 137 times less efficient at leaking information. This finding opens up an interesting avenue of research that could result in a safer future networking architecture.https://ieeexplore.ieee.org/document/8506363/Firewallinformation leakage attackname filternamed data networking
spellingShingle Daishi Kondo
Thomas Silverston
Vassilis Vassiliades
Hideki Tode
Tohru Asami
Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
IEEE Access
Firewall
information leakage attack
name filter
named data networking
title Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
title_full Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
title_fullStr Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
title_full_unstemmed Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
title_short Name Filter: A Countermeasure Against Information Leakage Attacks in Named Data Networking
title_sort name filter a countermeasure against information leakage attacks in named data networking
topic Firewall
information leakage attack
name filter
named data networking
url https://ieeexplore.ieee.org/document/8506363/
work_keys_str_mv AT daishikondo namefilteracountermeasureagainstinformationleakageattacksinnameddatanetworking
AT thomassilverston namefilteracountermeasureagainstinformationleakageattacksinnameddatanetworking
AT vassilisvassiliades namefilteracountermeasureagainstinformationleakageattacksinnameddatanetworking
AT hidekitode namefilteracountermeasureagainstinformationleakageattacksinnameddatanetworking
AT tohruasami namefilteracountermeasureagainstinformationleakageattacksinnameddatanetworking