首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >A Cross-Layer Anomaly-Based IDS for WSN and MANET
【2h】

A Cross-Layer Anomaly-Based IDS for WSN and MANET

机译:WSN和MANET的基于异常的跨层IDS

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Intrusion detection system (IDS) design for mobile adhoc networks (MANET) is a crucial component for maintaining the integrity of the network. The need for rapid deployment of IDS capability with minimal data availability for training and testing is an important requirement of such systems, especially for MANETs deployed in highly dynamic scenarios, such as battlefields. This work proposes a two-level detection scheme for detecting malicious nodes in MANETs. The first level deploys dedicated sniffers working in promiscuous mode. Each sniffer utilizes a decision-tree-based classifier that generates quantities which we refer to as correctly classified instances (CCIs) every reporting time. In the second level, the CCIs are sent to an algorithmically run supernode that calculates quantities, which we refer to as the accumulated measure of fluctuation (AMoF) of the received CCIs for each node under test (NUT). A key concept that is used in this work is that the variability of the smaller size population which represents the number of malicious nodes in the network is greater than the variance of the larger size population which represents the number of normal nodes in the network. A linear regression process is then performed in parallel with the calculation of the AMoF for fitting purposes and to set a proper threshold based on the slope of the fitted lines. As a result, the malicious nodes are efficiently and effectively separated from the normal nodes. The proposed scheme is tested for various node velocities and power levels and shows promising detection performance even at low-power levels. The results presented also apply to wireless sensor networks (WSN) and represent a novel IDS scheme for such networks.
机译:移动自组织网络(MANET)的入侵检测系统(IDS)设计是维护网络完整性的关键组件。这种系统的一项重要要求是快速部署IDS功能,并需要最少的数据来进行培训和测试,尤其是对于部署在战场等高动态场景中的MANET而言。这项工作提出了一种用于检测MANET中的恶意节点的两级检测方案。第一级部署以混杂模式工作的专用嗅探器。每个嗅探器都使用基于决策树的分类器,该分类器在每个报告时间生成数量,我们称其为正确分类的实例(CCI)。在第二级中,将CCI发送到算法运行的超级节点,该超级节点计算数量,我们称其为每个被测节点(NUT)接收到的CCI的波动累计量(AMoF)。在这项工作中使用的一个关键概念是,代表网络中恶意节点数量的较小规模种群的变异性大于代表网络中正常节点数量的较大规模种群的变异性。然后,为了进行拟合,并与计算AMoF并行执行线性回归过程,并根据拟合线的斜率设置适当的阈值。结果,恶意节点被有效地和有效地与正常节点分离。所提出的方案针对各种节点速度和功率水平进行了测试,即使在低功率水平下,也显示出有希望的检测性能。提出的结果也适用于无线传感器网络(WSN),并代表了用于此类网络的新颖IDS方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号