• DocumentCode
    1909466
  • Title

    Fighting Spam with the NeighborhoodWatch DHT

  • Author

    Bender, Adam ; Sherwood, Rob ; Monner, Derek ; Goergen, Nate ; Spring, Neil ; Bhattacharjee, Bobby

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Maryland, College Park, AK
  • fYear
    2009
  • fDate
    19-25 April 2009
  • Firstpage
    1755
  • Lastpage
    1763
  • Abstract
    In this paper, we present DHTBL, an anti-spam blacklist built upon a novel secure distributed hash table (DHT). We show how DHTBL can be used to replace existing DNS-based blacklists (DNSBLs) of IP addresses of mail relays that forward spam. Implementing a blacklist on a DHT improves resilience to DoS attacks and secures message delivery, when compared to DNSBLs. However, due to the sensitive nature of the blacklist, storing the data in a peer-to-peer DHT would invite attackers to infiltrate the system. Typical DHTs can withstand fail-stop failures, but malicious nodes may provide incorrect routing information, refuse to return published items, or simply ignore certain queries. The neighborhoodwatch DHT is resilient to malicious nodes and maintains the O(logiV) bounds on routing table size and expected lookup time. NeighborhoodWatch depends on two assumptions in order to make these guarantees: (1) the existence of an on-line trusted authority that periodically contacts and issues signed certificates to each node, and (2) for every sequence of k + 1 consecutive nodes in the ID space, at least one is alive and non-malicious. We show how NeighborhoodWatch maintains many of its security properties even when the second assumption is violated. Honest nodes in NeighborhoodWatch can detect malicious behavior and expel the responsible nodes from the DHT.
  • Keywords
    IP networks; cryptography; peer-to-peer computing; IP addresses; on-line trusted authority; peer-to-peer distributed hash table; table size routing; Communications Society; Computer crime; Databases; Peer to peer computing; Postal services; Relays; Resilience; Routing; Security; Unsolicited electronic mail;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2009, IEEE
  • Conference_Location
    Rio de Janeiro
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4244-3512-8
  • Electronic_ISBN
    0743-166X
  • Type

    conf

  • DOI
    10.1109/INFCOM.2009.5062095
  • Filename
    5062095