This paper proposes Random Time Challenge-Tokens (RTCT) as a mechanism to economically enforce honest participation and deter Sybil attacks at the network level, and shows that RTCT can exponentially increase an attacker’s costs with higher challenge difficulty, making networks more resilient.
Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightweight cryptographic mechanism that combines SHA-256 Proof-of-Work token mining with a time-windowed ratecontrol layer to limit the number of new identities a vehicle can activate within a given interval. The mechanism was implemented in Java and evaluated through a parametric simulation across three independent variables: PoW difficulty, rate limit, and attack intensity. Results show that a difficulty of 4 and a rate limit of 5 tokens per 10-second window provide an effective balance between Sybil resistance and legitimate vehicle access in an 8-vehicle scenario, with an average mining time of 0.227 seconds. The evaluation identifies the rate-control layer as the primary security mechanism, while PoW difficulty increases the computational cost per identity without independently capping accepted tokens. The proposed approach is infrastructure-free and suitable for regulated V2X deployments where attackers represent a minority of the network.
Maher Fayyad, Abdullah Awad, Edison Pignaton De Freitas et al.· International Conference on...· 0 citations
—Characteristics of Mobile Ad Hoc Networks (MANETs), such as decentralized architecture, shared communication medium, and node mobility, make them vulnerable to a variety of security threats. Sybil attack is one of the most challenging threats in which a malicious node pretends to be multiple distinct nodes to gain disproportionate resources and disrupt network functionalities. Several traditional solutions have been proposed in the literature, but they are either extensive in resource consumption or inadequate for the MANET context. This paper introduces a distributed lightweight method that exploits Sybil identities’ mobility correlation to detect the attack. It disseminates detection results using a lightweight hashing function. In addition, it uses a probation period to mitigate whitewashing attempts. Simulations using the INET framework under the OMNeT++ simulator, and an independent cross-validation under NS-3, reveal high detection accuracy up to 99.79% with a false positive rate of 0%. Our method can operate as a standalone solution or be integrated into existing routing protocols or IDSs.
This paper deals with security allocation challenges for networked control systems represented by positive-weighted digraphs under stealthy false data injection attacks. These systems consist of interconnected subsystems, referred to as nodes in the underlying digraph, where an adversary aims to maximize network performance loss by stealthily attacking specific nodes. Meanwhile, a defender monitors several nodes to impose stealthiness constraints on the adversary's actions, thereby minimizing the network performance loss. We analyze the worst-case network performance loss of these stealthy attacks and make the following contributions: we (i) show that the worst-case network performance loss is upper-bounded by a tractable semi-definite programming (SDP) problem; (ii) establish the relationship between the SDP problem and the Katz centrality measure of the underlying digraph under a sufficient condition, resulting in a network-size-independent optimization problem; and (iii) provide a heuristic search based on the Katz centrality measure of the underlying digraph for selecting sub-optimal monitor nodes against all admissible attack scenarios without solving optimization problems. These results offer practical insights for safeguarding large-scale networked control systems against stealthy false data injection attacks. The obtained results are validated via extensive simulations on Erdos-Renyi random graphs with different network sizes.
A. Nguyen, S. C. Anand, André M. H. Teixeira· 0 citations
Payment Channel Networks (PCNs) offer a scalable solution for off-chain cryptocurrency transactions, but suffer from low success rates and security challenges. A key issue lies in the lack of visibility into channel balances during route discovery, which prevents senders from reliably assessing whether a route can support the payment. To address this, we propose a routing protocol that integrates Secure Multiparty Computation (MPC) with a node reputation system. Our method enables senders to privately verify route feasibility before initiating Hash Time-Locked Contracts (HTLCs), reducing transaction failures. The node reputation system identifies and avoids unreliable nodes based on historical behavior, enhancing routing reliability even in adversarial settings. Experimental results on real Lightning Network snapshots across diverse parameter settings demonstrate that our approach substantially outperforms both the baseline shortest-path approach and the routing scheme used in the current Lightning Network implementation.
The high mobility and decentralized nature of Vehicular Ad Hoc Networks (VANETs) present significant security challenges. Specifically, detecting attacks and establishing secure, reliable routing protocols are major critical concerns in the vehicular environment. These attacks can significantly degrade network performance and hinder communication between vehicles. Insider attacks, such as Blackhole attacks, have the potential to severely disrupt VANET systems. This study introduces a novel trust management scheme that incorporates cryptographic techniques to address the important issues of secure routing in VANETs, which also helps in the detection of attacks. In this work, nodes' trust scores are evaluated, and the forwarding node for packet dissemination is chosen based on these scores. Furthermore, an elliptic curve cryptographic (ECC) signcryption technique is added for providing security to the network by authenticating the nodes, which mitigates the misbehaving nodes from the network. The simulation and comparative analysis show the efficacy of the proposed scheme. The proposed approach attained a packet delivery ratio (PDR) of 92.8%, indicating high reliability in data dissemination. Furthermore, the achieved results of throughput and End‐to‐End (E2E) delay are 232.32 KBps and 0.02 s, respectively. The obtained outcomes show enhancements of 94.182%, 49.67%, and 6% in PDR, throughput, and E2E delay, respectively, with respect to the existing techniques.
Nidhi Jaswani, Mou Dasgupta, Sangram Ray et al.· Security and Privacy· 0 citations
Peer-to-peer (P2P) overlay networks are the basis of numerous large-scale distributed applications since they provide the ability to share resources, distribute content, and offer collaborative services without a central authority. Nonetheless, due to the openness and dynamism nature of P2P systems, they are very susceptible to failures, node churning, network partitions and maliciousness. Creation of robust overlay network is hence critical in ensuring reliability, availability and performance during unfavorable conditions. In this paper, the design principles, threat models and protocol mechanisms necessary to create fault-tolerant and secure P2P overlays are investigated. It initially examines the main properties of structured and unstructured overlay networks with emphasis made to the topology construction of the networks, their maintenance mechanisms, and their routing mechanism. This paper will then examine some of the most critical failure and attack models such as dynamic membership changes, link failures, Byzantine nodes and coordinated attacks, which worsen overlay performance. Based on this discussion, the paper provides resilient protocol architecture design of join, leave, and reconfiguration procedures, and fault-tolerant routing and look-up algorithms, including Chord successor list routing, k-redundant path routing, and self-healing overlay routing. The issue of security conscious resilience mechanisms is also discussed to reduce malicious behavior without compromising scalability. As an analytical discussion and comparative assessment results in, the findings indicate that redundancy, adaptability and self-healing properties can enhance overlay robustness without incurring too much overhead. At the end of the paper, design trade-offs and future directions of resilient P2P overlay networks in new decentralized applications have been highlighted.
Dr. Sudhanshu Gonge¹, Dr Kalyani Kadam², Dr. Deepak Yashwant et al.· Journal of Intelligent Decis...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.