• DocumentCode
    63490
  • Title

    On the Security of End-to-End Measurements Based on Packet-Pair Dispersions

  • Author

    Karame, Ghassan O. ; Danev, B. ; Bannwart, C. ; Capkun, S.

  • Author_Institution
    ETH Zurich, Zurich, Switzerland
  • Volume
    8
  • Issue
    1
  • fYear
    2013
  • fDate
    Jan. 2013
  • Firstpage
    149
  • Lastpage
    162
  • Abstract
    The packet-pair technique is a widely adopted method to estimate the capacity of a path. The use of the packet-pair technique has been suggested in numerous applications including network management and end-to-end admission control. Recent observations also indicate that this technique can be used to fingerprint Internet paths. However, given that packet-pair measurements are performed in an open environment, end-hosts might try to alter these measurements to increase their gain in the network. In this paper, we explore the security of measurements based on the packet-pair technique. More specifically, we analyze the major threats against bandwidth estimation using the packet-pair technique and we demonstrate empirically that current implementations of this technique are vulnerable to a wide range of bandwidth manipulation attacks-in which end-hosts can accurately modify their claimed bandwidths. We propose lightweight countermeasures to detect attacks on bandwidth measurements; our technique can detect whether delays were inserted within the transmission of a packet-pair (e.g., by bandwidth shapers). We further propose a novel scheme for remote path identification using the distribution of packet-pair dispersions and we evaluate its accuracy, robustness, and potential use. Our findings suggest that the packet-pair technique can reveal valuable information about the identity/locations of remote hosts.
  • Keywords
    Internet; computer network security; Internet path; bandwidth estimation; bandwidth manipulation attack; bandwidth shaper; end-to-end admission control; end-to-end measurement security; network management; packet-pair dispersion; packet-pair technique; path capacity; remote host identification; remote host location; remote path identification; Accuracy; Bandwidth; Current measurement; Estimation; Gain measurement; Internet; Security; Measurement; security;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2012.2226579
  • Filename
    6341077