The Wayback Machine - https://web.archive.org/web/20240913174148/https://www.geeksforgeeks.org/sybil-attack/
Open In App

Sybil Attack

Last Updated : 11 Jul, 2022
Summarize
Comments
Improve
Suggest changes
Like Article
Like
Save
Share
Report
News Follow

Sybil Attack is a type of attack seen in peer-to-peer networks in which a node in the network operates multiple identities actively at the same time and undermines the authority/power in reputation systems. The main aim of this attack is to gain the majority of influence in the network to carry out illegal(with respect to rules and laws set in the network) actions in the system. A single entity(a computer) has the capability to create and operate multiple identities(user accounts, IP address based accounts). To outside observers, these multiple fake identities appear to be real unique identities.

History of Sybil Attack

The attack is named after the subject of the book Sybil (subject’s name is Sybil Dorsett). A paper called The Sybil Attack was written by John R. Douceur at the Microsoft Research.

Few Examples:

  • The recent alleged Russian interference in the United States’ election is a type of sybil attack in which multiple fake accounts on Facebook were operated. This attack falls in the category of pseudo-sybil attack because the platform used(Facebook) was not compromised itself.
  • Sybil attacks are carried on the Tor network.
  • The 51% attack in Blockchain networks.
  • Multiple fake reviews on Amazon and other e-commerce platforms by only one identity(such mass computing power is available(unethically) for hire from countries like Bangladesh.

Formal Model

The model used in the Sybil Attack paper is a simple one. It consists of:

  • E entities = c(correct) entities + f(faulty) entities

    correct – entities that follow the protocols and rules setup in the network honestly(whose honesty is verified).
    faulty – entities whose behavior are arbitrary and can’t be predicted. They don’t honestly follow the protocols and rules in the network.

  • A communication cloud: A very general cloud through which messages between different entities travel.
  • pipe: to connect an entity with the communication cloud
  • sybil attack formal model

    Types of sybil attack

    • In a direct attack, the honest nodes are influenced directly by the sybil node(s).
    • In an indirect attack, the honest node(s) are attacked by a node which communicates directly with the sybil node(s). This middle node is compromised as it’s under malicious influence of sybil node(s).

    How the Bitcoin network prevents sybil attack ?

    Bitcoin network uses the Proof of Work(PoW) consensus algorithm to prove the authenticity of any block that is added to the blockchain. A considerable amount of computing power is required to do the work which provides incentive to the miners to do honest work(a bitcoin reward; currently 12.5 bitcoins for every block mined) and no incentive for the faulty work. The transactions are verified by every node and rejected as invalid if faulty transactions are included in the block. A type of sybil attack, called the 51% attack is also practically impossible in the bitcoin network because of so many miners, it is very difficult for a single organization to control 51% of the miners.

    Ways to prevent sybil attack

    Giving different power to different members – This is on the basis of reputation systems. Members with different power levels are given different reputation levels.

    Cost to create an identity – To prevent multiple fake identities in the network, we can put a cost for every identity that aims to join the network. A point to note is that it makes more sense to make it infeasible to operate multiple fake identities at the same time rather than creating new identities. Multiple identities can enforce security, anonymity, censorship prevention.

    Validation of identities before joining the network –

    • Direct validation : An already established member verifies the new joiner of the network
    • Indirect validation: An established member verifies some other members who can, in turn, verify other new network joiners. As the members verifying the new joiners are verified and validated by an established entity, the new joiners are trusted to be honest.

     

    Note: Even though above techniques make it difficult to do sybil attack on the network, such attacks are not impossible.



Similar Reads

Rainbow Table Attack vs Dictionary Attack
Rainbow Table Attacks and dictionary attacks are the kinds of vector attacks in a computer system, the passwords are hashed using encryption rather than being saved as plain text directly where an attacker uses every word in a dictionary as a potential password to gain access to a password-protected system. The speed at which a password may be crac
6 min read
Difference between Active Attack and Passive Attack
In the field of cybersecurity, attacks on networks and systems are broadly classified into two categories: Active and Passive attacks. It is, therefore, important to understand the differences between these two types of attacks so that adequate security measures can be formulated. Active attacks call for the attacker to be involved in other actions
6 min read
Selective forwarding Attack in wireless Sensor Network
A selective forwarding attack is a type of security attack that can occur in wireless sensor networks (WSNs). In this attack, a malicious node in the network selectively forwards some data packets to the base station while dropping others, with the goal of compromising the integrity and availability of the network. The attacker can use various tech
8 min read
Wormhole Attack in Wireless Sensor Networks
This is a type of network layer attack which is carried out using more than one malicious node. The nodes used to carry out this attack are superior to normal nodes and are able to establish better communication channels over long ranges. The idea behind this attack is to forward the data from one compromised node to another malicious node at the o
4 min read
Brute Force Attack
A Brute force attack is a well known breaking technique, by certain records, brute force attacks represented five percent of affirmed security ruptures. A brute force attack includes 'speculating' username and passwords to increase unapproved access to a framework. Brute force is a straightforward attack strategy and has a high achievement rate. A
3 min read
What is a Dictionary Attack?
A Dictionary Attack is an attack vector used by the attacker to break in a system, which is password protected, by putting technically every word in a dictionary as a form of password for that system. This attack vector is a form of Brute Force Attack. The dictionary can contain words from an English dictionary and also some leaked list of commonly
2 min read
What is FTP Spoofing Attack?
FTP stands for file transfer protocol and it is an application layer protocol for transferring files between a client and a server. We can download, delete, move, rename, and copy files to a server using an FTP client. If you transfer a file using FTP, it will mostly upload or download data from the FTP server. When the files are uploaded, they are
5 min read
Sinkhole Attack in Wireless Sensor Networks
Sinkhole attacks are carried out by either hacking a node in the network or introducing a fabricated node in the network.The malicious node promotes itself as the shortest path to the base station and tries to guide the traffic from other nodes towards itself. This not only lures all the nodes near the sinkhole but also each and every node closer t
4 min read
US Maritime Attack
US maritime Ransomware Attack, 2019 : In today’s world, the USA is considered one of the superpower countries which have the world’s best facilities in everything from medical, transportation to military services.US military is considered as one of the most advanced militaries across the world. All these assumptions were questioned by an attack tha
2 min read
Replay Attack
Data has become very important to us in recent times. Safety and Security of data is of paramount importance. There are several confidential and sensitive information, which we cannot risk getting into wrong hands. However, sometimes an unauthorized person gets access to our information. Any action by an unauthorized person or hacker which poses a
2 min read
XML External Entity (XXE) and Billion Laughs attack
XXE or XML External Entity attack is a web application vulnerability that affects a website which parses unsafe XML that is driven by the user. XXE attack when performed successfully can disclose local files in the file system of the website. XXE is targeted to access these sensitive local files of the website that is vulnerable to unsafe parsing.
6 min read
Phishing Attack
Phishing is a type of cybersecurity attack that attempts to obtain data that are sensitive like Username, Password, and more. It attacks the user through mail, text, or direct messages. Now the attachment sends by the attacker is opened by the user because the user thinks that the email, text, messages came from a trusted source. It is a type of So
4 min read
Spear-Phishing Attack
This attack is used to target any specific organization or an individual for unauthorized access. These types of attacks are not initiated by any random hacker, but these attacks are initiated by someone who seeks information related to financial gain or some important information. Just like the phishing attack spear-phishing also comes from a trus
3 min read
MITM (Man in The Middle) Attack using ARP Poisoning
Introduction :Man In The Middle Attack implies an active attack where the attacker/Hacker creates a connection between the victims and sends messages between them or may capture all the data packets from the victims. In this case, the victims think that they are communicating with each other, but in reality, the malicious attacker/hacker controls t
5 min read
How SYN cookies are used to preventing SYN Flood attack
Before talking about SYN cookies and how they are used to preventing SYN Flood attack, Let us first take a look at how TCP connections were established until mid-1990s. How TCP Connection Are Established:A TCB(Transmission Control Block) is created when a TCP entity opens a TCP connection, A TCB contains whole state of connection. The state of the
5 min read
DOM-based Cross-Site Scripting Attack in Depth
In this article, we will be understanding one of the types of Cross-Site Scripting in-depth i.e DOM-based XSS. Let's discuss it one by one as follows. DOM-based Cross Site Scripting : DOM XSS stands for Document Object Model-based Cross-site Scripting. DOM-based vulnerabilities occur in the content processing stage performed on the client, typicall
4 min read
Remediation Planning against Cyber Attack
In this article we will see cybersecurity remedies and why it is so important. Due to the increasing number of ransomware and other cyber threats on the Internet, cyber-healing methods have become important. Much of the effort in cybersecurity is focused on preventing data breaches and protecting your company's digital assets. However, security mea
8 min read
How to Mitigate a DDoS Attack?
DDoS Attack :Distributed Denial of Service Attack is a sophisticated cyber attack, which is performed on digital assets, such as servers and computer systems. Primary aim of an attacker to executed this is to permanently shut down the target system or crash it for a long period of time, so that operations to be performed by user can be disturbed. I
5 min read
What is a DNS Amplification Attack?
DNS Amplification Attack :In this article, we will learn about the DNS Amplification Attack and how it can be prevented. A DNS (domain name system) Amplification Attack is basically a type of DDoS (denial-of-service) attack. It uses different technologies to attack the network by disabling it and not allowing legitimate users to use it. For launchi
3 min read
Pharming Attack Prevention and Examples
The term “Pharming” is a combinative word formed using farming and phishing. Pharming is a way of online fraud by cybercriminals that install some malicious code on your computer or server with fraudulent websites. The code is sent to the user through a bogus website, where the user may trick to provide personal information. Through this, the fraud
3 min read
How To Prevent Ransomware Attack?
Ransomware is a form of malware in which criminals attack a user's personal data and threaten the user to publish it online or Ransomware attackers can block the user's access to his data and ask to pay a ransom amount to unblock it. Ransomware is typically distributed via phishing emails with malicious attachments and drive-by downloading. It gene
6 min read
What is FTP Bounce Attack?
Prerequisite - File Transfer Protocol An FTP Bounce attack is an old type of network attack that is performed on FTP servers to send outbound traffic to a device typically another server in the network. It takes advantage of passive mode FTP, where the client is initiating both the control and data connections. The attacker issues a PORT command an
3 min read
What is a Directory Traversal Attack?
Directory Traversal Attack is a kind of Brute-force attack which will give potential access to restricted files and directories. This attack can also tell the attacker about the directory structure of the web application. It is very important to make web applications secure by giving protection to web content & giving controlled access. Directo
6 min read
What is ARP Spoofing? - ARP poisoning Attack
The ARP Poisoning, also known as ARP Spoofing, is a type of cyberattack that takes advantage of the ARP (Address Resolution Protocol). ARP is a protocol that maps an IP address to a MAC address within a local network. However, ARP lacks authentication mechanisms, and this is what the attack exploits. The attacker sends fake ARP responses to a speci
5 min read
Difference between Threat and Attack
Threats and attacks are two important aspects from a security point of view. A threat is malicious act, that has the potential to damage the system or asset while an attack is an intentional act that causes damage to a system or asset. In this article, we will understand threats and attacks, and the differences between them. What is a Threat?A thre
4 min read
Difference Between Password Spraying and Dictionary Attack
Cybercriminals can attack systems through password spraying or dictionary attacks, but they also do so in different ways. Password spraying attempts to break into multiple accounts using a few common passwords, while dictionary attacks use a list of many possible passwords against a single account. The attacker aims to find accounts with weak passw
7 min read
What is a Smurf Attack?
Smurf Attack: A Smurf attack is a type of distributed denial of service (DDoS) attack that interrupts an internet service by saturating the target with a large volume of unnecessary traffic, making it unavailable to regular users. It allows an attacker to increase the amount of traffic generated, to overwhelm the target’s network or device. Smurf a
5 min read
Password Attack vs Credential Stuffing
In the digital age in which we live, the technique of cybersecurity attacks keeps changing day by day and it has become significant to comprehend the thematic details of each sort of attack to secure information related to organizations. One of the key examples of digital risk exposure is password attack or credential stuffing. In this post, we exp
6 min read
Distributed Denial of Service DDoS attack
Imagine a scenario where you are visiting some websites and one of them seems to be a little slow. You might blame their servers for improving their scalability as they might be experiencing a lot of user traffic on their site. Most of the sites already take this issue into account beforehand. Chances are, they might be a victim of what is known as
6 min read
What is a Whaling Attack(Whaling Phishing)?
Whaling Attack, also known as Whaling Phishing, is a specific type of phishing attack that targets senior executives by using fake emails that appear legitimate. This kind of fraud is carried out through social engineering techniques with the aim of tricking the victim into taking a secondary action, such as transferring funds. The term "whaling" r
6 min read