Defending against sybil devices in crowdsourced mapping services

Gang Wang, Bolun Wang, Tianyi Wang, Ana Nika, Haitao Zheng, Ben Y. Zhao

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Real-time crowdsourced maps such as Waze provide timely updates on traffic, congestion, accidents and points of interest. In this paper, we demonstrate how lack of strong location authentication allows creation of software-based Sybil devices that expose crowdsourced map systems to a variety of security and privacy attacks. Our experiments show that a single Sybil device with limited resources can cause havoc onWaze, reporting false congestion and accidents and automatically rerouting user traffic. More importantly, we describe techniques to generate Sybil devices at scale, creating armies of virtual vehicles capable of remotely tracking precise movements for large user populations while avoiding detection. We propose a new approach to defend against Sybil devices based on co-location edges, authenticated records that attest to the one-time physical co-location of a pair of devices. Over time, colocation edges combine to form large proximity graphs that attest to physical interactions between devices, allowing scalable detection of virtual vehicles. We demonstrate the efficacy of this approach using large-scale simulations, and discuss how they can be used to dramatically reduce the impact of attacks against crowdsourced mapping services.

Original languageEnglish (US)
Title of host publicationMobiSys 2016 - Proceedings of the 14th Annual International Conference on Mobile Systems, Applications, and Services
PublisherAssociation for Computing Machinery, Inc
Pages179-191
Number of pages13
ISBN (Electronic)9781450342698
DOIs
StatePublished - Jun 20 2016
Externally publishedYes
Event14th Annual International Conference on Mobile Systems, Applications, and Services, MobiSys 2016 - Singapore, Singapore
Duration: Jun 25 2016Jun 30 2016

Publication series

NameMobiSys 2016 - Proceedings of the 14th Annual International Conference on Mobile Systems, Applications, and Services

Other

Other14th Annual International Conference on Mobile Systems, Applications, and Services, MobiSys 2016
Country/TerritorySingapore
CitySingapore
Period6/25/166/30/16

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Defending against sybil devices in crowdsourced mapping services'. Together they form a unique fingerprint.

Cite this