Delay based location verification for the internet

Page 1

Delay-Based Based Location Verification for the Internet

Abstract: The number of location-aware aware services over the Internet continues growing. Some of these require the client's geographic location for security-sensitive security applications. Examples include location location-aware aware authentication, location-aware location access policies, fraud prevention, vention, complying with media licensing, and regulating online gambling/voting. An adversary can evade existing geolocation techniques, e.g., by faking GPS coordinates or employing a non non-local local IP address through proxy and virtual private networks. We devis devise e Client Presence Verification (CPV), a delay-based based verification technique designed to verify an assertion about a device's presence inside a prescribed geographic region. CPV does not identify devices by their IP addresses. Rather, the device's location iiss corroborated in a novel way by leveraging geometric properties of triangles, which prevents an adversary from manipulating measured delays. To achieve high accuracy, CPV mitigates Internet path asymmetry using a novel method to deduce one-way one application-layer layer delays to/from the client's participating device, and mines these delays for evidence supporting/refuting the asserted location. We evaluate CPV through detailed experiments on PlanetLab, exploring various factors that affect its efficacy, including the granularity of the verified location, and the verification time. Results highlight the potential of CPV for practical adoption.


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.