Content Censorship in the InterPlanetary File System

Sridhar, Srivatsan;Ascigil, Onur;Keizer, Navin V.;Genon, François;Krol, Michal;et.al.
(2024) NDSS 2024: Network and Distributed System Security Symposium — Location: San Diego, USA (26.February.2024)

Files

2024-153-paper.pdf
  • Open Access
  • Adobe PDF
  • 1.23 MB

Details

Authors
  • Sridhar, SrivatsanStanford University
    Author
  • Ascigil, OnurUniversity of Lancaster
    Author
  • Keizer, Navin V.City, University of London
    Author
  • Genon, FrançoisUCLouvain
    Author
  • Pierre, SébastienUCLouvain
    Author
  • Author
  • Krol, MichalCity, University of London
    Author
Show more
Abstract
The InterPlanetary File System (IPFS) is currently the largest decentralized storage solution in operation, with thousands of active participants and millions of daily content transfers. IPFS is used as remote data storage for numerous blockchain-based smart contracts, Non-Fungible Tokens (NFT), and decentralized applications. We present a content censorship attack that can be executed with minimal effort and cost, and that prevents the retrieval of any chosen content in the IPFS network. The attack exploits a conceptual issue in a core component of IPFS, the Kademlia Distributed Hash Table (DHT), which is used to resolve content IDs to peer addresses. We provide efficient detection and mitigation mechanisms for this vulnerability. Our mechanisms achieve a 99.6% detection rate and mitigate 100% of the detected attacks with minimal signaling and computational overhead. We followed responsible disclosure procedures, and our countermeasures are scheduled for deployment in the future versions of IPFS.
Affiliations

Citations

Sridhar, S., Ascigil, O., Keizer, N. V., Genon, F., Pierre, S., Psaras, Y., Riviere, E., & Krol, M. (2024). Content Censorship in the InterPlanetary File System. Proceedings of the Network and Distributed System Security (NDSS) Symposium. Published. NDSS 2024: Network and Distributed System Security Symposium, San Diego, USA. https://hdl.handle.net/2078.5/256308