TY - JOUR
T1 - Rethinking Caching Security of Information-Centric Networking
T2 - A System Recovery Perspective
AU - Song, Tian
AU - Yang, Yating
AU - Li, Tianlong
N1 - Publisher Copyright:
© 1979-2012 IEEE.
PY - 2019/10
Y1 - 2019/10
N2 - ICN names data rather than hosts and then directly relays packets according to data names. This fundamental shift in naming from host-dependent to host-independent enables ICN to cache data for future service in its network. Therefore, ICN acts as not only a tunnel to transmit data but also a temporary cache of data, which inevitably confronts data attacks. In this article, for the first time, we investigate caching security from a system recovery perspective, and find that ICN attacked by typical caching attacks can be eventually recovered to the normal state if in-network security on data is provided. However, it may cause concern about the recovery time. To address this concern, we introduce a lightweight solution to shorten the recovery period of ICN by constructing and managing trusted zones with Dual Tunnels among Routers in a Penalty-Feedback Way (Duty). The feasibility and effectiveness of our design are verified by the experimental evaluations on real topology. Our work indicates a new perspective in the cache security of ICN and addresses some future work.
AB - ICN names data rather than hosts and then directly relays packets according to data names. This fundamental shift in naming from host-dependent to host-independent enables ICN to cache data for future service in its network. Therefore, ICN acts as not only a tunnel to transmit data but also a temporary cache of data, which inevitably confronts data attacks. In this article, for the first time, we investigate caching security from a system recovery perspective, and find that ICN attacked by typical caching attacks can be eventually recovered to the normal state if in-network security on data is provided. However, it may cause concern about the recovery time. To address this concern, we introduce a lightweight solution to shorten the recovery period of ICN by constructing and managing trusted zones with Dual Tunnels among Routers in a Penalty-Feedback Way (Duty). The feasibility and effectiveness of our design are verified by the experimental evaluations on real topology. Our work indicates a new perspective in the cache security of ICN and addresses some future work.
UR - http://www.scopus.com/inward/record.url?scp=85074109182&partnerID=8YFLogxK
U2 - 10.1109/MCOM.2019.1800864
DO - 10.1109/MCOM.2019.1800864
M3 - Article
AN - SCOPUS:85074109182
SN - 0163-6804
VL - 57
SP - 104
EP - 110
JO - IEEE Communications Magazine
JF - IEEE Communications Magazine
IS - 10
M1 - 8809573
ER -