首页> 外文学位 >Integrated prevention and detection of Byzantine attacks in mobile ad hoc networks.
【24h】

Integrated prevention and detection of Byzantine attacks in mobile ad hoc networks.

机译:移动ad hoc网络中对拜占庭式攻击的综合预防和检测。

获取原文
获取原文并翻译 | 示例

摘要

A mobile ad hoc network (MANET) consists of several wireless hosts that are capable of communicating with each other without the use of a network infrastructure or any centralized administration. Owing to the use of wireless channels and broadcasts for route discovery and maintenance techniques involving all nodes in the networks, MANETs are more vulnerable to security attacks than conventional wired and wireless networks. Byzantine attacks, in which attackers have full control of one or more authenticated nodes, collude with one another and use the most effective strategies to disrupt the network, are even more difficult to prevent and mitigate. Existing secure routing protocols (preventive solutions) do not handle such colluding Byzantine attacks well, and known intrusion detection techniques (post-attack solutions) are incomplete, and often inaccurate. Typically both approaches are software only solutions and lack experimental validation and/or vigorous theoretical justification.;In this dissertation, we provide an integrated solution to security issues in MANETs. Our solution consists of both secure routing protocols and support for reliable and efficient intrusion detection techniques (IDTs) to detect and mitigate attacks. We present new techniques to mitigate colluding attacks using software fortification at the network layer.;Through analysis of existing IDTs using analytical models, experiments on a testbed, and simulations, we show that software based intrusion detection systems are likely to be inaccurate and ineffective. Therefore we propose the use of limited hardware support to facilitate accurate and efficient intrusion detection. The hardware support is put in a new tamper-resistant communication (TRC) module between the network and data link layers. We identify the network-layer functionality that is incorporated within TRC, describe a log mechanism to record various network-layer events, and dissemination mechanisms that can be used to securely distribute these logs. We show the effectiveness of TRC in preventing, mitigating, or detecting a wide variety of known attacks. This combined with our current results on secure routing provides the most comprehensive and analyzed solutions to MANET security in the literature.
机译:移动自组织网络(MANET)由多个无线主机组成,这些主机能够相互通信,而无需使用网络基础结构或任何集中式管理。由于将无线信道和广播用于涉及网络中所有节点的路由发现和维护技术,因此MANET与常规的有线和无线网络相比,更容易受到安全攻击。攻击者完全控制一个或多个已认证节点,相互串通并使用最有效的策略来破坏网络的拜占庭式攻击更加难以预防和缓解。现有的安全路由协议(预防性解决方案)无法很好地处理此类串通的拜占庭式攻击,并且已知的入侵检测技术(攻击后解决方案)还不完善,而且常常不准确。通常,这两种方法都是纯软件解决方案,缺乏实验验证和/或有力的理论依据。在本文中,我们为MANET中的安全问题提供了一个集成解决方案。我们的解决方案既包括安全路由协议,又包括对可靠和高效的入侵检测技术(IDT)的支持,以检测和缓解攻击。我们提出了在网络层使用软件设防缓解共谋攻击的新技术。通过使用分析模型,在测试台上进行的实验和模拟对现有IDT进行分析,我们发现基于软件的入侵检测系统可能不准确且无效。因此,我们建议使用有限的硬件支持来促进准确和高效的入侵检测。硬件支持放在网络和数据链路层之间的新的防篡改通信(TRC)模块中。我们确定TRC中包含的网络层功能,描述一种记录各种网络层事件的日志机制,以及可用于安全分发这些日志的分发机制。我们展示了TRC在预防,缓解或检测各种已知攻击中的有效性。这与我们在安全路由上的最新结果相结合,为文献中的MANET安全提供了最全面,分析最多的解决方案。

著录项

  • 作者

    Su, Xu.;

  • 作者单位

    The University of Texas at San Antonio.;

  • 授予单位 The University of Texas at San Antonio.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 207 p.
  • 总页数 207
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号