TTLed Random Walks for Collaborative Monitoring

In this paper we discuss the problem of collaborative monitoring of applications that are suspected of being malicious. New operating systems for mobile devices allow their users to download millions of new applications created by a great number of individual programmers and companies, some of which...

Full description

Bibliographic Details
Main Authors: Altshuler, Yaniv, Dolev, Shlomia, Elovici, Yuval, Aharony, Nadav
Other Authors: Massachusetts Institute of Technology. Media Laboratory
Format: Article
Language:en_US
Published: Institute of Electrical and Electronics Engineers 2011
Online Access:http://hdl.handle.net/1721.1/61946
_version_ 1826207552733446144
author Altshuler, Yaniv
Dolev, Shlomia
Elovici, Yuval
Aharony, Nadav
author2 Massachusetts Institute of Technology. Media Laboratory
author_facet Massachusetts Institute of Technology. Media Laboratory
Altshuler, Yaniv
Dolev, Shlomia
Elovici, Yuval
Aharony, Nadav
author_sort Altshuler, Yaniv
collection MIT
description In this paper we discuss the problem of collaborative monitoring of applications that are suspected of being malicious. New operating systems for mobile devices allow their users to download millions of new applications created by a great number of individual programmers and companies, some of which may be malicious or flawed. The importance of defense mechanisms against an epidemic spread of malicious applications in mobile networks was recently demonstrated by Wang et. al. In many cases, in order to detect that an application is malicious, monitoring its operation in a real environment for a significant period of time is required. Mobile devices have limited computation and power resources and thus can monitor only a limited number of applications that the user downloads. In this paper we propose an efficient collaborative application monitoring algorithm called "TPP" - Time-To-Live Probabilistic Flooding, harnessing the collective resources of many mobile devices. Mobile devices activating this algorithm periodically monitor mobile applications, derive conclusion concerning their maliciousness, and report their conclusions to a small number of other mobile devices. Each mobile device that receives a message (conclusion) propagates it to one additional mobile device. Each message has a predefined TTL. The algorithm's performance is analyzed and its time and messages complexity are shown to be significantly lower compared to existing state of the art information propagation algorithms. The algorithm was also implemented and tested in a simulated environment.
first_indexed 2024-09-23T13:51:21Z
format Article
id mit-1721.1/61946
institution Massachusetts Institute of Technology
language en_US
last_indexed 2024-09-23T13:51:21Z
publishDate 2011
publisher Institute of Electrical and Electronics Engineers
record_format dspace
spelling mit-1721.1/619462022-09-28T16:37:18Z TTLed Random Walks for Collaborative Monitoring Altshuler, Yaniv Dolev, Shlomia Elovici, Yuval Aharony, Nadav Massachusetts Institute of Technology. Media Laboratory Program in Media Arts and Sciences (Massachusetts Institute of Technology) Aharony, Nadav Aharony, Nadav In this paper we discuss the problem of collaborative monitoring of applications that are suspected of being malicious. New operating systems for mobile devices allow their users to download millions of new applications created by a great number of individual programmers and companies, some of which may be malicious or flawed. The importance of defense mechanisms against an epidemic spread of malicious applications in mobile networks was recently demonstrated by Wang et. al. In many cases, in order to detect that an application is malicious, monitoring its operation in a real environment for a significant period of time is required. Mobile devices have limited computation and power resources and thus can monitor only a limited number of applications that the user downloads. In this paper we propose an efficient collaborative application monitoring algorithm called "TPP" - Time-To-Live Probabilistic Flooding, harnessing the collective resources of many mobile devices. Mobile devices activating this algorithm periodically monitor mobile applications, derive conclusion concerning their maliciousness, and report their conclusions to a small number of other mobile devices. Each mobile device that receives a message (conclusion) propagates it to one additional mobile device. Each message has a predefined TTL. The algorithm's performance is analyzed and its time and messages complexity are shown to be significantly lower compared to existing state of the art information propagation algorithms. The algorithm was also implemented and tested in a simulated environment. 2011-03-24T20:44:02Z 2011-03-24T20:44:02Z 2010-03 Article http://purl.org/eprint/type/ConferencePaper 978-1-4244-6739-6 0743-166X INSPEC Accession Number: 11308646 http://hdl.handle.net/1721.1/61946 Altshuler, Y. et al. “TTLed Random Walks for Collaborative Monitoring.” INFOCOM IEEE Conference on Computer Communications Workshops , 2010. 2010. 1-6. © 2010, IEEE en_US http://dx.doi.org/10.1109/INFCOMW.2010.5466697 IEEE INFOCOM (IEEE Conference on Computer Communications) Workshops Article is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use. application/pdf Institute of Electrical and Electronics Engineers IEEE
spellingShingle Altshuler, Yaniv
Dolev, Shlomia
Elovici, Yuval
Aharony, Nadav
TTLed Random Walks for Collaborative Monitoring
title TTLed Random Walks for Collaborative Monitoring
title_full TTLed Random Walks for Collaborative Monitoring
title_fullStr TTLed Random Walks for Collaborative Monitoring
title_full_unstemmed TTLed Random Walks for Collaborative Monitoring
title_short TTLed Random Walks for Collaborative Monitoring
title_sort ttled random walks for collaborative monitoring
url http://hdl.handle.net/1721.1/61946
work_keys_str_mv AT altshuleryaniv ttledrandomwalksforcollaborativemonitoring
AT dolevshlomia ttledrandomwalksforcollaborativemonitoring
AT eloviciyuval ttledrandomwalksforcollaborativemonitoring
AT aharonynadav ttledrandomwalksforcollaborativemonitoring