1. Electronic Engineering Department, Shanghai Jiao Tong University, Shanghai 200240, China;
2. School of Information Security Engineering, Shanghai Jiao Tong University, Shanghai200240, China
Abstract: In P2P (Peer-to-Peer) networks, some malicious peers can impact overall networks performance. One of the malicious behaviors of these peers is malicious packet dropping. In this paper, our focus is to detect and to exclude peers that misbehave by dropping some or all packets. Here, we propose a reputation-based mechanism for solving the problem efficiently. The proposed mechanism uses both direct reputation information and indirect reputation information to compute comprehensive reputation of a peer. At the same time, history reputation information is also taken into account when providing in faults tolerance capability and we regulate the imprecision based on the fact that the cause of packet dropping can be complex. Finally, the peers with bad comprehensive reputation can be detected easily and then will be excluded from the network. In this way, our proposed mechanism improves the performance of P2P networks without increasing computational overhead.
Received date: 2011-06-23
Foundation item: Supported by the National Key Basic Research Program of China(973 Program)(2010CB731403) and the Opening Project of Key Lab of Information Network Security of Ministry of Public Security (C09607).
Biography: PENG Hao, male, Ph.D. candidate, research direction: network communications and information security. E-mail: penghao2007@sjtu.edu.cn
0 Introduction
Peer-to-Peer (P2P)(正文中第一次出现缩写要先写全称后缩写,后文出现用缩写,专有名词首字母大写)networking hasbecome a very active research area in recent years because of its advantages over the traditional Client/Server model for applications like file sharing,distributed computing, collaborative applications, etc. However, the open nature of P2P networksmakes themvulnerablefor malicious peers trying to manipulate the network.
To solve this problem, many researchers have proposed various methods based on the reputation model and achieved degrees of success.There are mainly three kinds of reputation models: web-based, policy-based, and reputation-based reputation model [1,2](参考文献上标,并需在文中按数字顺序出现). These models can be directly or indirectly introduced into P2P networks to build reputation between peers. However, while peers’ identity privacy is important, it is difficult to be achieved in fully distributed P2P networks,because reputation usually depends on information related to identity.
Previous works have focused on developing various reputation models and enhancing identity privacy for P2P networks in a number of ways. Ref.[3](当以Ref.[*]类型出现时不上标)discusses the conflicts between privacy and reputation and proposes a trade-off model between them. In this model, it introduces multi-pseudonym to protect peers’ identity privacy. Although all the pseudonyms of a peer may not be linked together by attackers, privacy is not well protected because each pseudonym’s transaction can still be linked. Ref. [4] alleviates the identity privacy problem in reputation negotiation by hiding the peers’ credentials. However, the negotiation process also depends on the disclosure of information related to each peer’s identity. Ref.[5] proposes a reputation-based P2P network to achieve peers’ anonymity by changing the pseudonym. However, it is implemented using an online Trusted Third Part(TTP).
It is acknowledged that identity privacy in fully distributed P2P networks is desirable and necessary, but hard to achieve when building reputation. Therefore, in this paper we propose an assessmentmechanismfor P2P networks based on reputation to alleviate thisproblem. A reputation model is also developed to improve the safety of P2P networks by implementing a reputation management method.
The rest of the paper is structured as follows. Section 1 describes the proposed mechanism. Section 2simulates the mechanism and analyzes its performance. Finally, Section 3 concludes the paper.(引言中简单介绍研究背景,针对某些问题的研究现状,这些前人的研究存在某些不足,引出本文的研究。最后一段简单介绍本文的结构)
1 Proposed Mechanism
In our design, the way of preventing malicious packet dropping in P2P networks is the detection andexclusion mechanism.Neighbor detecting reputation mechanism has been suggested asa means to reduce the opposite effect ofmalicious peers. In this section, a reputation-basedmechanism will be stated in detail for detectingmalicious peers.
Our mechanism requires the followingassumptions to accomplish its functions properly:
① All peers can operate in local mode for neighbor detecting.
②Misbehaving peers are considered to be selfish andnot malicious.
③Intrusionprevention measures, suchas authentication and digital signature, serve as the first line of defense.
④The network is a multi-forwarding network.
1.1 Reputation Model
As mentioned above, the properties of P2P networks, such as peer-independence and lack of central management, means that detecting in P2P networks can only beperformed in a fully distributed way. Thus, eachpeer should be responsible for detecting itsneighbors’ behaviors for itself.
We present a reputation-basedassessment mechanism for detectingandexcludingmalicious peers. Theproposed mechanism relies on reputationmechanism for detecting neighbor peers’ forwarding and for computing whether a peer is malicious or not. Hereare some related definitions.
Definition 1 Assessment of direct reputation represents direct experience of detecting to a neighboring peer.
Definition 2 Assessment of indirect reputation re- presents thesynthesis resulting by aggregating multiplerecommendation opinions about a peer.
Definition 3 Assessment of comprehensive reputation represents the final evaluation to neighboringpeers. It can be defined as one peer’scomprehensive perception of another peer withregard to performing forwarding operation. Apeer with a good comprehensive reputationmeansit behaves very well, while peers with badcomprehensive reputation are malicious.
1.2 Assessment of Direct Reputation
In P2P networks, only fully distributeddetecting techniques can be applied in P2P networks because of the lack of a centralmanagement peer. Assessment of direct reputation in our mechanism depends on neighbor observations and analysis. Each peer overhearsits neighboring peers’ packet forwarding activities and detects any abnormal behaviors independently.
The reputationvalue is hard to quantify becausemany dynamic factors are involved. If a peer detects a packet dropping of aneighboring peer by overhearing, it cannot determinewhether the neighbor is selfish or failed to forwardbecause of congestion or collision. Then, anapproach based on fuzzy analysis can be used todeal with this problem.
In our design, the assessment of direct reputation is not onlyrelated to a peer’s packet-forwarding ratio,but also related to the busy state of peers. Considering these, we define a packet forwarding ratio andbusy degree to evaluate it. Peer “A[U14]” computes packet-forwarding ratio of peer “B”using the followingmetric:
(1)
In formula (1), is the number of packets forwarded by peer "B" during a fixed time, is the total number of packets forwarded by peer "B" during a fixed time.
Peer “A” computes peer “B” busy degreeusing the following metric:
In formula (2), is the number of packets forwarded by peer “B” per unit time,is the maximum number of packets that can beforwarded per unit time.
According to the rules above, peer “A”computes peer “B”direct reputation D (a, b) using thefollowing metric:
where is a weight of packet-forwarding ratio and is a weight of busy degree. Packet-forwarding ratio may be deemed to be more important than busy degree, so packet-forwarding ratio will be given greater weight in the reputation calculations.
1.3 Assessment of Indirect Reputation
Direct observations may not always be effective because of the weakness described in Ref. [6]. Ifa peer makes decisions only based on firsthandinformation, itis hard to make surewhetherall of its neighboring peers are normal or not. Using second-hand information canaccelerate the detection andsubsequent isolation of malicious peers in P2P networks.
Collaborative detection between peers can beachieved by broadcasting reputation information tothe neighboring peers. In our design, when peer “A”receivesrecommendation reputations of peer “B” from l neighboring peers, peer “A” computes the indirect reputation of peer “B”using the followingformula:
where is the recommendation reputation value of peer "B" from peer Ni and is the comprehensive reputation value of peer Ni stored in peer "A".
1.4 Assessment of Comprehensive Reputation
In our assessment mechanism, every peer has atablethatstores a comprehensive reputation value about its neighbors. Peer“A” updates the comprehensive reputation value of peer “B” onthe basis ofD(a,b)and.Peer“A”computescomprehensive reputationof peer “B”usingthe following formula:
where is the weight of the direct reputation and A peer can make bigger to increase the weight of its own observation and then to decrease bad influence caused by false information from misbehaving peers. When, it means the peer does not receive recommendation.
Reputation value should be updateddynamically because of the dynamic environmentin P2P networks. So our design takes into accountthe peer’s historical reputation, which helps us calculate a peer’s comprehensive reputation. In this way, peer “A” can compute the comprehensive reputationof peer “B”using the following formula:
The first part describes the comprehensive reputation value of peer ‘B’ figured in the reputation value table of peer“A” in the past. The secondpartreflects the peer B’s newcomprehensive reputation value computedcurrently based on formula (5).is the weight of the peer’s past comprehensive reputation value and. If, history reputation value will play animportant role and vice-versa.
Each comprehensive reputation isinitialized to 0.5.The lower the comprehensive reputation thepeer has, the higher the possibility of misbehavior thepeer has. When the comprehensive reputation value of a peer is below acertain threshold, it is broadcasted to all theneighboring peers.
2 Simulation Results
To evaluate the effectiveness of the proposed assessment mechanism, a software simulator built from scratch is adopted. In our simulation design, we use a mesh topology with 25000 peers selected randomly. This mesh represents a general topology and it can also be applied to specific P2P networks. The simulator relies on a discrete time paradigm and the time step is equal to 225 ms.
To perform the simulation analysis, we adopted the following parameter values. For the sake of clarity only 10 minutes of the overall simulation is presented. To obtain a realistic simulation we limited the available bandwidth. According to the application characteristics of P2P networks, the bandwidth is unable to keep a sustained speed of 5.00 Mb/s, but rather tends to stabilize around a maximum 2.75 Mb/s. The movement of all peers was randomly generated with a maximum speed of 2.5Mb/s and an average pause of 30s. Each simulation runs 500 simulation seconds. The result is shown in Fig. 1. The vertical axis shows the comprehensive reputation value in different forwarding rate, while the horizontal shows the time.
From Fig.1, it is found that normal peers can obtain a high reputation value ranging from 0.787 to 0.964 after a while; the comprehensive reputation of a peer that forwards packets with a rate of 80% can reach a reputation value ranging from 0.609 to 0.824. As the forwarding rate decreases, the comprehensive reputation of the malicious peer decreases from the value 0.5 to a value close to 0.011 gradually.
The changing of comprehensive reputation is gradual. This is because we takehistory reputation into consideration anddeliberate that faults are tolerant. However,the differences of comprehensive reputation between malicious peer and normalpeers are still obvious. In this way, we can decide to select which peers to communicateand isolate the maliciouspeers.
Fig. 1 Comparison of comprehensive reputations of different forwarding rates
3 Conclusion
In this paper, we proposed a reputation-based mechanism to counter malicious packet dropping in P2P networks. It can offer defense against malicious peers and improve the peer’s quality of service, thus it can ensure P2P network’s communication security and robustness. However, the mechanism proposed in the paper only uses a reputation threshold to avoid attackers and then attackers in P2P networks may also adjust adaptively. To enhance our design here, in future work, we will introduce other mechanisms such as anonymity and load balance to optimize the mechanism.
