PMFA: Toward Passive Message Fingerprint Attacks on Challenge-Based Collaborative Intrusion Detection Networks

Wenjuan Li, Weizhi Meng, Lam-For Kwok, Ho Shing Ip

Research output: Chapter in Book/Report/Conference proceedingArticle in proceedingsResearchpeer-review

Abstract

To enhance the performance of single intrusion detection systems (IDSs), collaborative intrusion detection networks (CIDNs) have been developed, which enable a set of IDS nodes to communicate with each other. In such a distributed network, insider attacks like collusion attacks are the main threat. In the literature, challenge-based trust mechanisms have been established to identify malicious nodes by evaluating the satisfaction between challenges and responses. However, we find that such mechanisms rely on two major assumptions, which may result in a weak threat model and make CIDNs still vulnerable to advanced insider attacks in practical deployment. In this paper, we design a novel type of collusion attack, called passive message fingerprint attack (PMFA), which can collect messages and identify normal requests in a passive way. In the evaluation, we explore the attack performance under both simulated and real network environments. Experimental results indicate that under our attack, malicious nodes can send malicious responses to normal requests while maintaining their trust values.
Original languageEnglish
Title of host publicationProceedings of the 10th International Conference on Network and System Security (NSS 2016)
PublisherSpringer
Publication date2016
Pages433-449
ISBN (Print)978-3-319-46297-4
ISBN (Electronic)978-3-319-46298-1
DOIs
Publication statusPublished - 2016
Event10th International Conference on Network and System Security - Taipei, Taiwan, Province of China
Duration: 28 Sept 201630 Sept 2016
Conference number: 10
http://nsclab.org/nss2016/

Conference

Conference10th International Conference on Network and System Security
Number10
Country/TerritoryTaiwan, Province of China
CityTaipei
Period28/09/201630/09/2016
Internet address
SeriesLecture Notes in Computer Science
Volume9955
ISSN0302-9743

Keywords

  • Intrusion Detection System
  • Collaborative network
  • Insider threats
  • Collusion attacks
  • Challenge-based trust mechanism

Fingerprint

Dive into the research topics of 'PMFA: Toward Passive Message Fingerprint Attacks on Challenge-Based Collaborative Intrusion Detection Networks'. Together they form a unique fingerprint.

Cite this