BloomCasting: Security in Bloom Filter Based Multicast

نویسندگان

  • Mikko Särelä
  • Christian Esteve Rothenberg
  • András Zahemszky
  • Pekka Nikander
  • Jörg Ott
چکیده

Traditional multicasting techniques give senders and receivers little control for who can receive or send to the group and enable end hosts to attack the multicast infrastructure by creating large amounts of group specific state. Bloom filter based multicast has been proposed as a solution to scaling multicast to large number of groups. In this paper, we study the security of multicast built on Bloom filter based forwarding and propose a technique called BloomCasting, which enables controlled multicast packet forwarding. Bloomcasting group management is handled at the source, which gives control over the receivers to the source. Cryptographically computed edge-pair labels give receivers control over from whom to receive. We evaluate a series of data plane attack vectors based on exploiting the false positives in Bloom filters and show that the security issues can be averted by (i) locally varying the Bloom filter parameters, (ii) the use of keyed hash functions, and (iii) per hop bit permutations on the Bloom filter carried in the packet header.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

BloomCasting for Publish/Subscribe Networks

Aalto University, P.O. Box 11000, FI-00076 Aalto www.aalto.fi Author Mikko Särelä Name of the doctoral dissertation BloomCasting for Publish/Subscribe Networks Publisher School of Electrical Engineering Unit Department of Communications and Networking Series Aalto University publication series DOCTORAL DISSERTATIONS 49/2011 Field of research Networking Technology Manuscript submitted 14 October...

متن کامل

On the Security of In-Packet Bloom-Filter Forwarding

Multicast protocols traditionally require that routers store information about the delivery trees. Recently, source-routed in-packet Bloom-filter (iBF) based multicast has been proposed as a remedy to this: instead of storing state in the network, the delivery tree is encoded in the packet itself using a Bloom filter. The packets are then forwarded based on the in-packet information instead of ...

متن کامل

Defending Against DDoS Attacks in Bloom Filter based Multicasting

Bloom filter (BF) based forwarding is an effective approach to implement scalable multicasting in distributed systems. The forwarding BF carried by each packet can encode either multicast tree or destination IP addresses, which are termed as tree oriented approach (TOA) and destination oriented approach (DOA), respectively. Recent studies have indicated that TOA based protocols have serious vul...

متن کامل

Bloom Filter-Based Ad Hoc Multicast Communication in Cyber-Physical Systems and Computational Materials

This article presents an efficient ad hoc multicast communication protocol for next-generation cyber-physical systems and computational materials. Communication with such systems would be gestural, and when cells within such materials detect a motion, they would share that information with each other. We want to achieve efficient communication among only the group of nodes that sense a particul...

متن کامل

XBF: Scaling up Bloom-filter-based Source Routing

A well known drawback of IP-multicast is that it requires per-group state to be stored in the routers. Bloom-filter based source-routed multicast remedies this problem by moving the state from the routers to the packets. However, a fixed sized Bloom-filter can only store a limited number of items before the false positive ratio grows too high implying scalability issues. Several proposals have ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010