TY - JOUR
T1 - Towards statistically strong source anonymity for sensor Networks
AU - Yang, Yi
AU - Shao, Min
AU - Zhu, Sencun
AU - Cao, Guohong
PY - 2013/5
Y1 - 2013/5
N2 - For sensor networks deployed to monitor and report real events, event source anonymity is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may attack against sensor source privacy through traffic analysis, but also because sensor networks are very limited in resources. As such, a practical trade-off between security and performance is desirable. In this article, for the first time we propose the notion of statistically strong source anonymity, under a challenging attack model where a global attacker is able to monitor the traffic in the entire network.We propose a scheme called FitProbRate, which realizes statistically strong source anonymity for sensor networks.We demonstrate the robustness of our scheme under various statistical tests that might be employed by the attacker to detect real events. Our analysis and simulation results show that our scheme, besides providing source anonymity, can significantly reduce real event reporting latency compared to two baseline schemes. However, the degree of source anonymity in the FitProbRate scheme might decrease as real message rate increases.We propose a dynamic mean scheme which has better performance under high real message rates. Simulation results show that the dynamic mean scheme is capable of increasing the attacker's false positive rate and decreasing the attacker's Bayesian detection rate significantly even under high-rate continuous real messages.
AB - For sensor networks deployed to monitor and report real events, event source anonymity is an attractive and critical security property, which unfortunately is also very difficult and expensive to achieve. This is not only because adversaries may attack against sensor source privacy through traffic analysis, but also because sensor networks are very limited in resources. As such, a practical trade-off between security and performance is desirable. In this article, for the first time we propose the notion of statistically strong source anonymity, under a challenging attack model where a global attacker is able to monitor the traffic in the entire network.We propose a scheme called FitProbRate, which realizes statistically strong source anonymity for sensor networks.We demonstrate the robustness of our scheme under various statistical tests that might be employed by the attacker to detect real events. Our analysis and simulation results show that our scheme, besides providing source anonymity, can significantly reduce real event reporting latency compared to two baseline schemes. However, the degree of source anonymity in the FitProbRate scheme might decrease as real message rate increases.We propose a dynamic mean scheme which has better performance under high real message rates. Simulation results show that the dynamic mean scheme is capable of increasing the attacker's false positive rate and decreasing the attacker's Bayesian detection rate significantly even under high-rate continuous real messages.
UR - http://www.scopus.com/inward/record.url?scp=84896945628&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84896945628&partnerID=8YFLogxK
U2 - 10.1145/2480730.2480737
DO - 10.1145/2480730.2480737
M3 - Article
AN - SCOPUS:84896945628
SN - 1550-4859
VL - 9
JO - ACM Transactions on Sensor Networks
JF - ACM Transactions on Sensor Networks
IS - 3
M1 - 2480737
ER -