Distrust in the DHT: How Routing Attacks Cripple Decentralized Social Networks

The Impact of Routing Attacks on Pastry-Based P2P Online Social Networks

2014-01-01
Felix A. Eichert, Markus Monhof, Kalman Graffi
Summary
Problem
Method
Results
Takeaways
Abstract

This paper investigates the vulnerability of the Pastry distributed hash table (DHT) to three specific routing attacks: DROP, LDF, and AMP, within the context of decentralized peer-to-peer (P2P) social networks. Through large-scale simulations using PeerfactSim.KOM, the authors demonstrate that even a minority of malicious nodes can severely degrade network performance or lead to total lookup failure.

TL;DR

Decentralized social networks promise freedom from censorship, but they are built on a fragile foundation: trust. This paper explores how malicious nodes can exploit the Pastry DHT—the backbone of the LifeSocial platform—using clever routing subversions. By shifting from simple packet dropping to deceptive "slow-routing" strategies, attackers can bloat network latency and resource consumption without being easily detected.

Context: The Social P2P Landscape

The rise of centralized giants like Facebook has highlighted risks of censorship and data mining. Peer-to-Peer (P2P) alternatives like LifeSocial use Pastry, a Structured Overlay, to store data across a global network of users. In Pastry, every node is equal, and messages are routed based on "NodeID" proximity. However, because routing is performed by neighbors, the system is inherently vulnerable to those who refuse to follow the protocol.

The Anatomy of Subversion: Three Attack Strategies

The authors identify and simulate three distinct ways an adversary can break the network:

  1. DROP (Blocking any Request): The "Black Hole" approach. A node participates in the network but refuses to forward any message that isn't for itself.
  2. LDF (Largest Distance First): The "Detour" approach. Instead of moving the message closer to the target, the attacker sends it to the known node furthest from the destination. This maximizes hops and physical travel distance.
  3. AMP (Approach at Minimum Pace): The "Stalling" approach. The attacker moves the message toward the target, but only by the smallest possible increment. This is the most insidious attack because it mimics "correct" behavior while drastically slowing the network.

Concept of Routing Deviation Fig 1: Illustrating how malicious nodes redirect traffic away from the optimal path.

Methodology: High-Fidelity Simulation

Using PeerfactSim.KOM, the researchers simulated networks of 1,000 and 10,000 nodes. They introduced varying "contamination levels" (from 0% to 50% malicious nodes) to measure two key metrics: Lookup Success Rate and Average Hops per Lookup.

Critical Results: Efficiency vs. Availability

The results reveal a stark contrast between "loud" and "quiet" attacks:

  • The Availability Crisis (DROP): As seen in the figure below, the DROP strategy is devastating. In a 10,000-node network, a 30% malicious ratio causes nearly 80% of lookups to fail. Because longer paths (more hops) are more likely to hit a malicious node, larger networks are actually more vulnerable to this attack.
  • The Efficiency Drain (LDF & AMP): Interestingly, LDF and AMP have negligible effects on the success rate (remaining near 100% success). However, the cost of success sky-rockets. The number of hops required to find a piece of data increases linearly with the number of attackers, turning a high-performance DHT into a sluggish, overloaded system.

Failed Lookups Analysis Fig 2: The exponential impact of DROP attacks on lookup success as malicious node ratios increase.

Hop Count Comparison Fig 3: The LDF strategy causes a much sharper increase in hop counts compared to the more "polite" AMP strategy.

Deep Insight: Why Detection is the Next Frontier

The paper concludes that Pastry, in its vanilla form, is insufficiently robust for a truly "indestructible" social network. While DROP attacks are easy to detect (the destination is never reached), AMP and LDF are far more dangerous for the long-term health of a P2P community. They consume the bandwidth and CPU of honest nodes while providing just enough service to avoid being blacklisted.

Future Outlook

For P2P social networks to survive, developers must move beyond simple DHTs toward "Secure Overlays." This includes:

  • Reputation Systems: Tracking which neighbors consistently provide low-latency, "direct" routes.
  • Verifiable Path Histories: Using cryptographic proofs to ensure a message actually took the shortest logical path.
  • Redundant Routing: Sending requests through multiple disjoint paths to bypass clusters of malicious nodes.

Without these, decentralized social networks remain a "fair-weather" technology, vulnerable to any organized group that wishes to silence the conversation by simply slowing it down to a crawl.

Find Similar Papers

Try Our Examples

  • Search for recent papers proposing reputation-based defense mechanisms specifically designed to mitigate "Approach at Minimum Pace" (AMP) attacks in DHTs.
  • What are the foundational theories behind "Secure Routing" in structured P2P overlays as proposed by Castro et al. (2002), and how does this paper build upon those failure models?
  • Explore how the routing attack strategies identified in this paper (DROP, LDF, AMP) could be applied to harm modern decentralized systems like InterPlanetary File System (IPFS) or Ethereum's Discovery Protocol.
Contents
Distrust in the DHT: How Routing Attacks Cripple Decentralized Social Networks
1. TL;DR
2. Context: The Social P2P Landscape
3. The Anatomy of Subversion: Three Attack Strategies
4. Methodology: High-Fidelity Simulation
5. Critical Results: Efficiency vs. Availability
6. Deep Insight: Why Detection is the Next Frontier
7. Future Outlook