首页> 外文会议>International Symposium on Recent Advances in Intrusion Detection(RAID 2006); 20060920-22; Hamburg(DE) >DEMEM: Distributed Evidence-Driven Message Exchange Intrusion Detection Model for MANET
【24h】

DEMEM: Distributed Evidence-Driven Message Exchange Intrusion Detection Model for MANET

机译:DEMEM:MANET的分布式证据驱动的消息交换入侵检测模型

获取原文
获取原文并翻译 | 示例

摘要

A Mobile Ad Hoc Network (MANET) is a distributed communication platform for mobile wireless nodes. Because of the lack of a centralized monitoring point, intrusion detection systems (IDS) for MANET are usually developed using a distributed architecture where detectors are deployed at each node to cooperatively detect attacks. However, most of these distributed IDS simply assume that each detector exchanges complete information with their peers instead of establishing an efficient message exchanging protocol among detectors. We propose a Distributed Evidence-driven Message Exchanging intrusion detection Model (DEMEM) for MANET that allows the distributed detector to cooperatively detect routing attacks with minimal communication overhead. The framework allows detectors to exchange evidences only when necessary. Under a few practical assumptions, we implement DEMEM to detect routing attacks the Optimal Link State Routing (OLSR) protocol. The example scenarios and performance metrics in the experiment demonstrate that DEMEM can detect routing attacks with low message overhead and delay, no false negatives, and very low false positives under various mobility conditions with message lost. Our ongoing works include implementing DEMEM in AODV, DSR and TBRPF, and a reputation-based cooperative intrusion response model.
机译:移动自组织网络(MANET)是用于移动无线节点的分布式通信平台。由于缺少集中的监视点,因此通常使用分布式体系结构来开发MANET的入侵检测系统(IDS),在该体系结构中,在每个节点处部署检测器以协作检测攻击。但是,大多数这些分布式IDS只是假设每个检测器都与其对等方交换完整的信息,而不是在检测器之间建立有效的消息交换协议。我们提出了一种针对MANET的分布式证据驱动的消息交换入侵检测模型(DEMEM),该模型允许分布式检测器以最小的通信开销协作检测路由攻击。该框架仅允许检测者在必要时交换证据。在一些实际的假设下,我们实现DEMEM来检测路由攻击最佳链路状态路由(OLSR)协议。实验中的示例场景和性能指标表明,DEMEM可以在各种消息丢失的情况下,以各种消息开销和延迟,无误报和极低的误报检测路由攻击。我们正在进行的工作包括在AODV,DSR和TBRPF中实现DEMEM,以及基于信誉的协作入侵响应模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号