首页> 外文会议>Latest trends in information technology >Application of Forensic Analysis for Intrusion Detection against DDoS Attacks in Mobile Ad Hoc Networks
【24h】

Application of Forensic Analysis for Intrusion Detection against DDoS Attacks in Mobile Ad Hoc Networks

机译:法医分析在移动Ad Hoc网络中针对DDoS攻击的入侵检测中的应用

获取原文
获取原文并翻译 | 示例

摘要

This paper addresses a specific approach to resolving the problem of intrusion detection against distributed denial of service (DDoS) attacks in mobile ad hoc networks (MANET). Generally, the main function of an intrusion detection system (IDS) is to inspect the network for malicious activities, policy violations and security loopholes integrity, and to generate the appropriate reports. Network forensics concerns examining a network for anomalous traffic and identifying intrusions. It is particularly useful in decreasing of the likelihood of reoccurrence of the same intrusion activities. In the first part of the paper, we provide a comprehensive-overview of recent advances in network forensics in MANET environment. In the second part of the paper, we propose a model of IDS that uses network forensics to detect DDoS attack in MANET. The forensic analysis relies on inspecting simultaneous malicious activities of a group of attackers (zombies). Since DDoS attack traffic can appear rather alike to legitimate traffic in the sense of bit rate and packet size, the applied method should minimize the risk of misinterpreting legitimate traffic as attack traffic (false positives). Further, since DDoS zombies are actually mobile nodes, which can follow different mobile patterns and have different speeds, particular attention has been focused to individual and group mobility models. Finally, we present a performance analysis of the proposed model that comprises the node number, node speed, attack duration and the influence of applied mobility patterns. The study has been carried out by the network simulator ns-2 and its associated tools for mobility scenario generation, network animation and trace files analysis.
机译:本文提出了一种解决移动Ad hoc网络(MANET)中针对分布式拒绝服务(DDoS)攻击的入侵检测问题的特定方法。通常,入侵检测系统(IDS)的主要功能是检查网络是否存在恶意活动,违反策略和安全漏洞的完整性,并生成适当的报告。网络取证涉及检查网络中的异常流量并识别入侵。在减少相同入侵活动再次发生的可能性中特别有用。在本文的第一部分,我们提供了MANET环境中网络取证的最新进展的全面概述。在本文的第二部分中,我们提出了一种IDS模型,该模型使用网络取证来检测MANET中的DDoS攻击。法医分析依赖于检查一组攻击者(僵尸)的同时恶意活动。由于DDoS攻击流量在比特率和数据包大小的意义上看起来与合法流量非常相似,因此所应用的方法应将误认为合法流量为攻击流量的风险降至最低(误报)。此外,由于DDoS僵尸实际上是移动节点,可以遵循不同的移动模式并具有不同的速度,因此特别关注了个人和团体移动性模型。最后,我们对提出的模型进行性能分析,其中包括节点数,节点速度,攻击持续时间以及所应用的移动性模式的影响。这项研究是由网络模拟器ns-2及其相关工具进行的,用于移动场景的生成,网络动画和跟踪文件分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号