• No results found

Managing Resource and Servent Reputation in P2P Networks

N/A
N/A
Protected

Academic year: 2021

Share "Managing Resource and Servent Reputation in P2P Networks"

Copied!
9
0
0

Loading.... (view fulltext now)

Full text

(1)

Managing Resource and Servent Reputation in P2P Networks

Abstract

The openness and anonymity of P2P file-sharing networks have been widely accepted over the last few years. Enormous file-sharing communities in which numerous anonymous users share a variety of resources have been established with the aid of the P2P networks. Users can join the communities with ease without disclosing their identities. However, the openness and anonymity raises the problem of trust, because openness and anonymity also assist malicious users in exploiting the networks and, at the same time, complicate their detection and location.

We propose a remedy for this trust problem by introducing a new reputation management model. The unique features of applying reputations to both resources and servents, and dividing the servent reputations into contribution score and evaluation score allow the model to represent the servents’ past behavior more accurately. We demonstrate the robustness of our reputation model by subjecting it to several known attacks.

1. Introduction

Over the last years, we have witnessed an explosion in the popularity of Peer-to-Peer (P2P) file sharing. Unlike the traditional client-server model, in which the roles of nodes are fixed, clients request resources and servers provide them, the P2P model lets every node (servents) play the roles of both server and client. The model connects servents in a decentralized and autonomous fashion, allowing servents to join and withdraw from the P2P networks freely without disclosing their true identity. The flexibility and scalability of the model enable users to participate in large-scale file sharing communities with ease. Examples of such P2P file sharing networks include Napster, Gnutella, and Freenet.

The open and anonymous nature of P2P networks raises the problem of servent trust. Malicious servents may exploit the networks to distribute Trojan horses and viruses [9]. They can also implement spamming by answering positive to all queries and then offering fake resources. The trust issue is hard to solve. Because of openness, malicious servents can “inject” their resources and “fly away” instantly, and because of anonymity, malicious servents can exploit the network while exposing only their pseudonyms. Both aspects make the detection and tracing of malicious servents difficult in P2P networks.

An effective solution to this trust problem is to utilize reputation [10]. Reputation, a summary of a servent’s past behavior, is a powerful tool for predicting the servent’s future actions. A history of a resource receiving positive evaluations from multiple servents is a powerful reason for trusting that resource. This paper presents a new model for managing reputation. The model assigns reputation scores to both resources and servents, and these reputation scores interact mutually and autonomously in the model in such a way as to make the reputation model robust against attacks. Furthermore, the model scores servent reputation in two categories, servent contribution score and servent evaluation score, to represent the servents’ past behavior more accurately.

Section 2 reviews previous works on reputation management in P2P networks. Section 3 overviews our reputation management model in detail. Section 4 proves the robustness of our model by showing that our model can resist several attacks known to have been directed against P2P reputation management systems. Section 5 discusses a method for implementing our reputation management model in completely decentralized P2P networks.

Makoto Iguchi

NTT Information Sharing

Platform Laboratories

[email protected]

Masayuki Terada

NTT DoCoMo Multimedia

Laboratories

[email protected]

Ko Fujimura

NTT Information Sharing

Platform Laboratories

[email protected]

(2)

2. Related Works

A well-known example of a reputation management system is eBay's system [7]. After a transaction, the participants (buyer and seller) evaluate each other and vote their ratings. The ratings are aggregated to form the reputation score for each participant. The score acts as a reference when a participant wants to interact with another participant for the first time.

Some of the previous works on reputation systems on P2P networks use a similar approach [1] [6]. Their models basically adopt eBay’s idea for use in a distributed environment. After the transaction, each servent rates the partner (servent) according to her experience during the transaction. For example, she may rate the partner negatively if she finds the downloaded file unacceptable (e.g. if the file was actually a virus). These ratings are kept locally in a distributed manner, and later are aggregated to formulate the overall reputations of servents. While the models successfully manage the servent reputations so as to provide references for users in judging servent trustworthiness, they introduce the cold start problem for newcomers. New servents without past transaction records have to interact with other servents to create their reputations, yet their low reputations as newcomers hinder them from participating in P2P file sharing activities. It is desirable to give newcomers a chance to build their reputation. For instance, it is better if newcomer servents could build their reputations by downloading reputable resources from existing servents, by evaluating the resource properly, and by sharing these reputable resources with P2P network members. In this case, the servents are actually contributing to the P2P file-sharing network in two ways; by evaluating the quality of the resources properly and by sharing reputable resources.

Another method, introduced by Damiani et al., combines the reputations of servents and resources [4]. By introducing resource reputations, the model successfully takes advantage of both servent reputations and resource reputations. The introduction of resource reputations makes it possible for newcomer servents to immediately participate in file sharing activities by distributing well-known resources. The link between the resource reputations and the servent reputations, however, is weak in their model. It is desirable to weight the votes made by servents on resources in such a way that the evaluations made by reputable

servents have a greater impact on the resource reputation than those made by disreputable servents. While the concept of “servent credibility” [3] is introduced in their model to achieve a similar purpose, their credibility score is merely a reference for judging whether to trust the votes submitted by the corresponding servents. We believe that “servent credibility” should have more direct impact on the resource reputation; the amount the resource reputation increases should be weighted by the “credibility” of the voting servent.

3. Reputation Management Model

3.1. Basic Assumptions

Our reputation management model links the reputations of resources and servents as follows.

Resource reputation score Ri represents the trustworthiness of resource ri. The resource reputation score is a measure that summarizes the past record of the evaluations (votes) submitted for the resource. A high Rivalue indicates that resource rihas received positive votes from servents.

We use two scores to determine servent reputation, namely servent contribution score, SCi,and servent evaluation score, SEi,for servent si. SCi is a measure that summarizes the past behavior of si relative to its resource contribution. A high SCi value indicates that the resources provided by si are regarded as trustworthy by other servents. SEiis a measure that summarizes the past behavior of si relative to its resource evaluations. A high SEivalue indicates that the evaluations provided by si are regarded as reliable by other servents. Our model treats the contribution score and the evaluation score separately, because the probability of a servent contributing trustable resources and the probability of a servent issuing reliable resource evaluations are totally different.

We formulate these reputations using the following assumptions:

1. A resource is trustable if a servent who has offered trustable resources is providing it. 2. A resource is trustable if servents who have

been evaluating resources reliably support it. 3. A servent’s contribution is trustable if the resources provided by the servent have received positive votes.

4. A servent’s evaluation is reliable if resources on which the servent has voted

(3)

positively (negatively) have received positive (negative) votes from other servents.

Assumption (1) allows a resource reputation score to be assigned to a newly introduced resource. There is no history about the new resource, so it is reasonable to determine its initial resource reputation score from the servent contribution score of the servent providing the resource. We derive the following:

Resource reputation score Ri of newly introduced resource ri, introduced by servent si, is derived from the servent contribution score SCi of si.

Assumption (2) allows a resource reputation score to be updated upon receiving a vote on the resource. The updating procedures are as follows. First, it is reasonable to regard a resource receiving positive votes from multiple servents as trustable. Second, if there exist two votes, one submitted by a servent with low servent evaluation score and the other by a servent with high servent evaluation score, it is reasonable to weight the latter vote more heavily when updating the resource reputation score. The same notion applies for negative votes. This yields the following:

Resource reputation score Ri of existing resource ri {increases/decreases} as the resource ri receives {positive/negative} vote from servent sj, and the influence of the vote is a function of the servent evaluation score SEj of sj.

Assumption (3) allows the servent contribution scores to be updated. Each servent contribution score should be updated so as to express the latest status of the servent and to render assumption (1) valid. Since the servent contribution score is a measure that represents the trustworthiness of resources provided by the servent, the contribution reputation should be accumulated as the resource reputation scores of the resources provided by the servent increase. The same notion applies to the depletion of the servent contribution score. Updating can be described as follows:

Servent contribution score SCi of servent si {increases/decreases} as resource reputation Ri of resource ri that the servent si has

contributed to the P2P network {increases/

falls}.

Assumption (4) allows the servent evaluation scores to be updated. The servent evaluation score should be updated so as to express the latest status of the servent and to make assumption (2) valid. Since the servent evaluation score is a measure that represents the reliability of votes provided by the servent, the score should be accumulated as the votes made by the servent are found to be reliable. The collaborative nature of the reputation system, in which numerous servents cooperate with regard to resource evaluations, yield the following definition of “reliable vote”: “a vote that evaluates a resource in compliance with the majority decision”. Updating can be described as follows:

Servent evaluation score SEj of servent sj {increases/decreases} as the resource reputation Ri of resource ri on which the servent sj has voted changes in the {same/opposite} direction.

3.2. Reputation management

implementation

Let us now explain our reputation management model in more detail. Here, we will concentrate our discussion on a “Napster-like” centrally coordinated P2P file sharing system. (See Section 5 for discussion on implementing our reputation management model on decentralized P2P systems).

The central server manages the reputations of both servents and resources along with a list of resources shared by active servents. In response to a query sent by a servent, the central server returns the reputation information to the servent along with the download candidate lists. Servents, after downloading the resources, evaluate the resources and submit their votes to the central server.

The central server maintains the following reputation-related information:

1. Resource reputations: for each resource shared on the P2P network; the server maintains a set of resource identifiers and resource reputation scores.

2. Servent evaluation/contribution reputations: for each servent on the P2P network; the server maintains a set of servent identifier,

(4)

servent contribution score, and servent evaluation score.

3. Votes submitted by servents: for each resource shared on the P2P network; the server maintains the votes submitted on the resource. The server also maintains the identifiers of the servents who submitted the votes.

Resource identifiers and servent identifiers are used for indexing purposes, and so should be uniquely defined for each resource and servent. One example is to use a digest of the resource content calculated by a secure hash function as the resource identifiers, and to use non-overlapping pseudonyms, registered on the central server, as the servent identifiers.

Our reputation management model consists of four phases: sending a file list to the central server, locating the target resource/servent, selecting and downloading target resource/ servent, and voting and updating resource and servent reputations.

Phase 1: Sending a file list to the central server

Upon connecting to the P2P network, a servent sends a list of resources and associated descriptions to the central server. (The servent also sends additional information such as its IP address and port number that will be used when establishing actual connections for resource transfer). For reputation management purposes, the servent also calculates the resource identifiers associated with the resources, and sends these resource identifiers and its own server identifier to the central server as well (Fig. 1).

Figure 1. Sending a file list to the server The central server adds the list of resources and associated descriptions to its directory index. Then, for each resource identifier it receives, the central server checks to see if the corresponding resource reputation score already exists. If

there is no resource reputation score associated with the resource identifier (i.e. the resource is new), the server calculates the score and stores the result. The calculation is based on the servent contribution score of the corresponding servent. For the case where servent si with servent contribution score SCi introduces new resource ri, the resource reputation score Ri of resource ri is calculated by the following equation:

i

i

SC

R

=

(1)

The equation is a straightforward implementation of assumption (1) described in Section 3.1.

Phase 2: Locating target resource/servent

The servent submits a query to the central server. The central server returns a list of matching resources and a list of servents who possess the resources. The corresponding resource reputation scores and the servent contribution scores are also returned to the servent (Fig. 2).

Figure 2. Locating target resource/servent

Phase 3: Selecting and downloading target resource/servent

Using the information given in Phase2, the servent selects the target resource (to download) and the target servent (from where the target resource is to be downloaded). The selection is up to the user, but most likely the following policies would be applied:

1) If there are multiple resources that match the query, the user will select the resource with the highest resource reputation score. Theoretically, the servent can pick any servent that offers the resource, but most users will feel comfortable in selecting the Servent Server

(servent_id, resource list) ack

Compute resource reputation scores for newly introduced resources

Servent Server (search condition)

(resource info, servent info+)*

resource info := {resource id, resource reputation score, resource description}*

(5)

servent with the highest contribution reputation score.

2) If all of the candidate resources have relatively low scores, the user will refer to the servent contribution score instead and select the resource offered by the servent with the highest servent contribution score. For example, suppose the response to a query is as shown in Table 1. The servent can choose either 1) resource “Cool mpeg” with the resource reputation score of 3, and download it from either servent “X-man” or “Y-wing”, or 2) regard the resource reputation score of 2 and 3 as too low, and instead focus on servent “ZZZ” with the servent contribution score of 7 and decide to download the resource “Cool movie” from the servent “ZZZ”.

Table 1. An example of response to query

Having chosen the target resource and servent, the servent accesses the target servent and downloads the target resource.

Phase 4: Voting and updating resource/servent reputations

After downloading the resource, the servent evaluates the resource and submits a vote to the central server. The actual content of the vote is a real value ranging from –1 to +1. A positive value represents satisfaction with the resource, whereas a negative value represents dissatisfaction.

After receiving the vote, the central server updates the corresponding resource and servent reputation scores (Fig. 3).

Figure 3. Voting and updating resource/servent reputations

First, the resource reputation score of the downloaded resource is updated. The update procedure follows assumption (2) of Section 3.1. If resource ri is downloaded by servent sj with servent evaluation score SEj and vote eji is then submitted by servent sj on ri, resource reputation score Ri is recalculated as follows:

j ji

i

e

SE

R

=

(2)

Since the resource reputation score is updated, the servent contribution score of the servent who provided the resource is also updated. Servent contribution score SCi of servent si (the servent who has offered resource ri) is recalculated as follows:

i

i

R

SC

=

(3)

where

R

i is the change in the resource reputation score as calculated by Equation (2). Note that the update procedure follows assumption (3) of Section 3.1.

The change in the resource reputation score also affects the servent evaluation scores of all servents who have been voting on the resource, following assumption (4) described in Section 3.1. If servents sk (k=1, 2 … n) have submitted votes eki on resource ri, each servent evaluation score SEk of sk (k=1, 2 … n) is recalculated as follows: i ki k

e

R

SE

=

(k=1,2, … n) (4) where ∆Ri is the change in the resource reputation score as calculated by Equation (2). Note that

SE

kbecomes:

- Positive if

e

ki and

R

i have the same sign (i.e. the votes submitted by servents sk have the same direction as the change in the resource reputation score)

- Negative if

e

ki and

R

i have different signs (i.e. the votes submitted by servents sk are opposite to the change in the resource reputation score)

4. Security Considerations

Recent studies on reputation management systems point out that several attacks against them are possible [5] [8] [10]. We analyzed the Cool mpeg (Score:3)

Cool movie (Score:2)

Resource Candidates

X-man (Contribution Score: 4) Y-wing (Contribution Score: 3)

Servent sharing the resources

ZZZ (Contribution Score: 7) Iguchi (Contribution Score: 1)

Servent Server (servent_id, resource id, vote)

ack

Update the corresponding reputation scores

(6)

robustness of our reputation management model by subjecting it to these attacks.

4.1. Reputation nullification

The simplest attack against the reputation system is exploiting “cheap pseudonyms” [8]. In this attack, a malicious servent misbehaves for a while, discards its pseudonym, and registers a new pseudonym with a fresh servent reputation; The servent can discard her negative reputation and pickup a new reputation.

Our reputation model can counter this attack by setting the initial servent reputation score under the lowest possible servent reputation score. This makes the reputation nullification attack unprofitable, because a newly registered servent always has a lower reputation score than its previous score.

It may seem that this countermeasure would discourage newcomers. The newcomers might be demoralized if their low servent reputation impedes them from participating in the activities. The reputation model we propose alleviates this problem in two ways. First, we introduce the resource reputation score; newcomers can actively participate in file sharing activities from the beginning by sharing resources with high reputation. By offering highly reputable resources to the P2P network, they can easily build their servent contribution score. Second, we clearly divide the servent contribution score from the servent evaluation score. The algorithm we use to calculate the servent evaluation score provides newcomers with a chance to increase their servent evaluation score quickly by rating downloaded resources correctly.

4.2. Reputation self-manipulation

Some servents may try to manipulate their servent reputations. If there is a way to cheat the reputation algorithm, the malicious servents will exploit the weakness to manipulate the reputation scores in their favor. Fortunately, our reputation algorithm prevents this type of attack. Both the servent contribution score and the servent evaluation score require the concurrence of other servents to increase their reputations, as shown in Equations (3) and (4) in Section 3.2. The servent contribution score only increases when the resource that the servent has provided receives positive votes from other servents, and the servent evaluation score only

increases when the resource on which the servent has submitted a {positive/negative} vote {gains/loses} its resource reputation by receiving {positive/negative} votes from other servents.

The fact that other servents’ witnesses are needed to change the reputations suggests a possible attack of simulating witnesses. The pseudospoofing attack [10], for example, exploits the “cheap pseudonym” natures of the reputation system by controlling multiple pseudonyms simultaneously and simulating fake witnesses. For example, a malicious user can increase servent A’s contribution score by simulating resource download from servent A to pseudo servents B and C and by voting positively on the resource as servents B and C. A straightforward countermeasure is to restrict such simulations by assigning only one pseudonym to each user. This can be easily achieved by checking users in the pseudonym registration process. If this check is unfeasible, however, other countermeasures should be applied. (In this case, the countermeasures for another type of attack, the shilling attack, can be applied. Refer to the discussion on “shilling attack” in the next section).

4.3. Reputation manipulation through

collusion

Instead of deceiving the reputation system alone, several malicious servents may decide to collude to manipulate the reputations. Shilling is an attack of this type; in the attack, conspirator servents submit positive votes on a resource provided by their friend’s servent to strengthen her reputation (ballot stuffing) or negative votes on a resource provided by their competitor servent to weaken her reputation (bad-mouthing) [5] [10]. Unlike the pseudospoofing attack, the votes come from “real” servents in the shilling attack, so “one pseudonym per user” tactic is no barrier to the shilling attack.

Our reputation model can block the shilling attack through the servent evaluation score. In our model, shilling is effective only if the servents submitting fake votes have high servent evaluation scores. It is unlikely, however, that servents with high evaluation scores will engage in shilling attacks because the actions will degrade their evaluation scores. Shilling attacks performed by servents with low evaluation scores have little impact on overall reputations, making the attack ineffective. Therefore, conspirators have to strengthen their

(7)

servent evaluation scores prior to conducting the attack. Unfortunately for them, building strong evaluation scores requires a past history of reliable vote submission, and constructing such records is time-consuming. Note that offering multiple resources to the P2P network to create the appearance of a trustworthy servent cannot fool our reputation management mechanism, because the trick might strengthen the contribution score of the servent (which is totally legitimate) but will not strengthen the evaluation score of the servent.

The effectiveness of shilling is further minimized in our model because the overall reputations are calculated by aggregating votes from numerous servents. The malicious servents would have to persuade a large number of servents to submit shills in order to manipulate reputations.

5. Implementation on decentralized

P2P networks

So far, we have described our reputation management model with a “Napster-like” centrally coordinated P2P network in mind. Recently, another type of P2P network, namely the completely decentralized P2P network, has been attracting attention. In this type of P2P network, there is no central server responsible for coordinating servents (i.e. providing a directory of resources). Gnutella and Freenet are examples of systems with this type.

When applying our reputation management model to completely decentralized P2P file sharing systems, the following issues have to be solved.

1) There is no central server to store resource and servent reputations securely.

2) There is no central server to collect votes submitted by servents.

The first problem can be solved by making each servent keep track of her own reputation-related information (i.e. the information that are derived from her experience with other servents). The second problem can be dealt with by requesting other servents to send their opinions (votes they have submitted) on a resource as the need arises.

More precisely, each servent is required to hold the following local reputation-related information.

1. Resource reputations: The servent maintains a set of resource identifiers and resource reputation scores for each resource that she has experience with (i.e. resources that the servent has previously downloaded).

2. Servent evaluation/contribution reputations: The server maintains a set of servent identifier, servent contribution score, and servent evaluation score for each servent that she has experienced with (i.e. the servents that she has previously downloaded resources from).

3. Votes submitted by servents: the servent maintains a set of a vote submitted on the resource and an identifier of the servent who submitted the vote for each vote that she has submitted when she has downloaded the resource and for each vote that she has experienced with (i.e. the vote that the servent has collected from other servents. See Phase 2 below for more details).

In this condition, our reputation model can be implemented on a decentralized P2P network as follows:1

Phase 2: Locating target resource/servent

A servent broadcasts a query to the P2P network. Servents possessing resources that match the query respond with a set of {ri, si} where ri is an identifier of the resource and si is an identifier of the responding servent.

After receiving the responses, the servent determines a temporary resource reputation for each ri it receives using the following rules: - If resource reputation score Riof resource ri

exists in the local reputation-related information, use this value as the temporary score.

- If Ri does not exist but servent contribution score SCi of the servent siexists in the local reputation-related information, then the temporary resource score is calculated using equation (1) in Section 3.2 and servent contribution score SCi.

- If both Riand SCi do not exist, the servent first assigns a new SCi (and also SEi). The servent then calculates the temporary resource score using equation (1). SCi is usually set low because servent si is a “newcomer”.

1 Phase 1 is omitted because the phase is irrelevant in a decentralized P2P network environment.

(8)

Next, for each ri, the servent broadcasts another query and asks other servents to send their votes on ri. Servents who have previously downloaded ri respond to the query with a set of {sj, eji} where sj is the responding servent’s identifier and eji is a vote that sj has submitted on ri.

The servent, after receiving the responses, updates the resource reputation by applying equation (2) in Section 3.2 for each {sj, eji} it receives. While updating the resource reputation, the follow rules apply:

- If servent evaluation reputation score SEj of sj exists in the local reputation-related information, the servent updates Ri by applying this SEjand eji to equation (2). - If SEj does not exist in the local

reputation-related information, the servent first assigns a new SEj (and also SCj). The servent then updates Riby applying this SEjand eji to equation (2). Here, SEj is usually set low because servent sj is a “newcomer”.

The servent may receive {sj, eji} from a servent whose vote is already part of her local reputation-related information. In this case, an appropriate action, such as discarding old vote, should be taken in order to prevent reflecting multiple votes from the same servent on Ri.

Phase 3: Selecting and downloading target resource/servent

Using the information determined in Phase 2, the servent selects the target resource and the target servent. Details of this selection strategy are the same as in the centrally coordinated P2P network scheme.

Phase 4: Voting and updating resource/ servent reputations

After downloading the resource, the servent evaluates it. The result of the evaluation, vote e, is then used to update the resource reputation Ri using equation (2).

The change in Ri triggers an update of server contribution score SCi of the target servent si. This is done using equation (3) in Section 3.2. In this scenario, however, ǍRi is defined as: (Ri just after reflecting vote e) – (the temporary Riin Phase 2).

The change in Ri also triggers updates of servent evaluation scores SEkof all servents sk who have sent their votes on ri. This is done by applying equation (4) in section 3.2; this time Ǎ Ri is defined as: (Riafter reflecting vote e) – (the

temporary Riin Phase 2) –

e

ki

SE

k. In other words, ǍRi used for updating SEk is defined as the fluctuation caused by all votes collected in Phase 2, excluding the vote submitted by servent sk itself.

Finally, the servent updates her local reputation-related information so as to reflect new Ri,SCk, and SEk calculated in Phase 4. Note that the above implementation works effectively only if attacks conducted by malicious servents to pollute others’ local reputation by submitting fake votes with fake identities are prevented. Fortunately, some techniques for preventing such attacks in decentralized P2P networks have been proposed in [4], and we believe that applying similar techniques will allow our reputation management model to conquer this problem.

Another problem that should be considered is the “self-centered local reputation” problem. Collecting all votes from all servents in P2P network in Phase 2 is not realistic, so it is practical to collect votes only from servents who reside near the vote-collecting servent. The local reputation at each servent is thus constructed with limited scope, allowing deviation in the local reputation maintained at each servent. For instance, servent A may “overestimate” average-quality servent B as “very reliable” if the votes servent A collects about servent B happen to be all positive. This is a weakness of the distributed local reputation scheme compared to the centrally-coordinated global reputation scheme, in which the reputation is constructed using all votes submitted by all servents. One solution for alleviating this weakness is to introduce the concept of “reputation equalization”. Its basic idea is to periodically refer to other servents’ local reputation, and adjust one’s own local reputation if it differs significantly from other’s reputation. We believe that a technique similar to the trust updating method employed in Poblano [2] can be applied to achieve equalization of local reputation. Establishing the actual methodology for achieving such local reputation equalization, however, requires more discussion and is part of future work.

6. Conclusion

This paper has proposed a reputation management model for P2P file sharing networks. We have shown that our mechanism,

(9)

which is based on mutually interacting resource reputation scores, servent contribution scores, and servent evaluation scores, realizes an effective and robust reputation scoring system.

7. References

[1] K. Aberer and Z. Despotovic, “Managing Trust in a Peer-2-Peer Information Systems”, Proc. of 10th International Conference on Information and Knowledge Management (CIKM 2001), 2001.

[2] R. Chen and W. Yeager, “Poblano: A Distributed Trust Model for Peer-to-Peer Networks”, Sun Microsystems Technical Paper, 2000, http://www.sun.com/ software/jxta/poblano.pdf.

[3] F. Cornelli, E. Damiani, S. De Capitani di Vimercati, S. Paraboschi, and P. Samarati, “Choosing Reputable Servents in a P2P Network”, Proc. of 11th International World Wide Web Conference, 2002. [4] E. Damiani, De Capitani di Vimercati, S. Paraboschi, P. Samarati, and F. Violante, “A Reputation-Based Approach for Choosing Reliable Resources in Peer-to-Peer Networks”, Proc. of 9th ACM Conference on Computer and Communication Security, 2002.

[5] C. Dellarocas, “Immunizing Online Reputation Reporting System Against Unfair Rating and Discriminatory Behavior”, Proc. of 2nd ACM Conference on Electronic Commerce, 2000.

[6] R. Dingledine, M. J. Freedman, and D. Molnar, “The Free Haven Project: Distributed Anonymous Storage Service”, Proc. of the Workshop on Design Issue in Anonymity and Unobservability, 2000. [7] Ebay. http://www.ebay.com/.

[8] E. Friedman and Paul Resnick, “The Social Cost of Cheap Reputation”, Telecommunication Policy Research Conference, 1998.

[9] A. K. Ghosh, and M. Schmid, “Execution Control Lists: An Approach to Defending Against New or Unknown Malicious Software”, Proc. of 3rd Information Survivability Workshop (ISW2000), 2000. [10] A. Oram, editor, Peer-to-Peer: Harnessing the Power of Disruptive Technologies, O’Reilly & Associates, 2001.

References

Related documents

In this article, we proposed a multi-objective model to optimally control the resources allocated to the service stations in a multi-server dynamic PERT network for both

It is a type of network operating systems that share resources among computer connected to the network without central control is called____________.. Peer to peer network

However, roughly half of enterprise storage systems today are based on the Network File System (NFS), a type of distributed file system that consolidates data resources