• DocumentCode
    2045733
  • Title

    On the Privacy of Peer-Assisted Distribution of Security Patches

  • Author

    Wu, Di ; Tang, Cong ; Dhungel, Prithula ; Saxena, Nitesh ; Ross, Keith W.

  • Author_Institution
    Sun Yat-Sen Univ., Guangzhou, China
  • fYear
    2010
  • fDate
    25-27 Aug. 2010
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    When a host discovers that it has a software vulnerability that is susceptible to an attack, the host needs to obtain and install a patch. Because centralized distribution of patches may not scale well, peer-to-peer (P2P) approaches have recently been suggested. There is, however, a serious privacy problem with peer-assisted patch distribution: when a peer A requests a patch from another peer B, it announces to B its vulnerability, which B can exploit instead of providing the patch. Through analytical modeling and simulation, we show that a large majority of vulnerable hosts will typically become compromised with a basic design for peer- assisted patch distribution. We then study the effectiveness of two different approaches in countering this privacy problem. The first approach utilizes special-purpose peer nodes, referred to as honeypots, that discover and blacklist malicious peers listening for patch requests from susceptible hosts. In the second approach, the patches are requested through an anonymizing network, hiding the identities of susceptible hosts from malicious peers. Using analytical models and simulation, we show that, honeypots do not completely solve the privacy problem; in contrast, an anonymizing network turns out to be more suitable for security patch distribution.
  • Keywords
    data privacy; peer-to-peer computing; anonymizing network; centralized distribution; honeypots; peer-assisted patch distribution; privacy problem; security patches; software vulnerability; Analytical models; Bandwidth; Grippers; Peer to peer computing; Privacy; Security; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Peer-to-Peer Computing (P2P), 2010 IEEE Tenth International Conference on
  • Conference_Location
    Delft
  • Print_ISBN
    978-1-4244-7140-9
  • Electronic_ISBN
    978-1-4244-7139-3
  • Type

    conf

  • DOI
    10.1109/P2P.2010.5569988
  • Filename
    5569988