Re: Possible Fix for Dynamic Querying?...and kill Spammers to boot!
"Elias Athanasopoulos" <[email protected]>
| Newsgroups | gmane.network.gnutella.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello! On Thu, Mar 01, 2007 at 06:04:04AM -0000, sellick_david wrote: > Maybe UltraPeers could do a quick spammer spot-test?: randomly > generate 8 characters (with or without vowels for twice the fun) and > send that as a search query to every newly connected UltraPeer or > Leaf. It's highly likely that anything that replies to that search > query is a spammer. This would only be a stop-gap measure to eliminate > spammers, as they will likely adopt smarter reply strategies were this > test commonplace. I don't think any of these solutions may work. I have also thought some of them in the past, but nothing really valuable can come out. Consider the following scenario: a malicious peer is connected to Gnutella as a legitimate peer and instead of replying to every Query it routes, it just changes the IP address of every QueryHit it routes. That is, the malicious peer does not inject spam QueryHits in the system, but changes the identity carried by legitimate QUeryHits in the system. How can you fight this one? Also, this attack may be more stealthy. Inject 10 malicious peers (very easy) and let them change 1 of 10 QueryHits they route... Regards, -- Elias Athanasopoulos Distributed Computing Systems (DCS) Institute of Computer Science (ICS/FORTH) Heraklion, Crete A bug can become a feature by documenting it.