首页> 外文期刊>Ad hoc networks >Spoofing detection in IEEE 802.15.4 networks based on received signal strength
【24h】

Spoofing detection in IEEE 802.15.4 networks based on received signal strength

机译:基于接收信号强度的IEEE 802.15.4网络中的欺骗检测

获取原文
获取原文并翻译 | 示例

摘要

The shared medium used in wireless networks makes them vulnerable to spoofing attacks, in which an adversary masquerades as one or more legitimate nodes to disturb normal operation of the network. In this paper we present a novel spoofing detection method for static IEEE 802.15.4 networks based on spatial correlation property of received signal strength (RSS). While most existing RSS based techniques directly process RSS values of the received frames and rely on multiple traffic air monitors (AMs) to provide an acceptable detection performance, we extract features of RSS streams to reduce data redundancy and provide a more distinguishable representation of the data. Our algorithm employs two features of RSS streams, summation of detailed coefficients (SDCs) in discrete Haar wavelet transform (DHWT) of the RSS streams and the ratio of out-of-bound frames. We show that in a typical scenario, a single AM with SDC as detection parameter, can theoretically outperform a system with 12 AMs which directly applies RSS values as detection parameter. Using ratio of out-of-bound frames facilitates detection of high rate attacks. In addition, we suggest adaptive learning of legitimate RSS values which enhances the robustness of the attack detector against environmental changes. Using both magnitude and frequency related features, we achieved high detection performance with a single AM; this enables development of preventive measures for spoofing attacks. The performance of our approach was evaluated through an IEEE 802.15.4 testbed in an office environment. Experimental results along with theoretical analysis show that the proposed method outperforms the existing RSS-based spoofing detection solutions. Using a single AM, we were able to attain 94.75% detection rate (DR) with 0.56% false positive rate (FPR). For 4 AMs, the results improved to 99% DR and 0% FPR.
机译:无线网络中使用的共享介质使它们容易受到欺骗攻击,在这种欺骗攻击中,对手会伪装成一个或多个合法节点,以干扰网络的正常运行。在本文中,我们基于接收信号强度(RSS)的空间相关性,提出了一种针对静态IEEE 802.15.4网络的新型欺骗检测方法。尽管大多数现有的基于RSS的技术都直接处理接收到的帧的RSS值,并依靠多个交通空中监控器(AM)来提供可接受的检测性能,但我们提取RSS流的功能以减少数据冗余并提供更可区分的数据表示形式。我们的算法利用了RSS流的两个特征:RSS流的离散Haar小波变换(DHWT)中的详细系数(SDC)的总和以及出边界帧的比率。我们显示,在典型情况下,以SDC作为检测参数的单个AM在理论上可以胜过具有12 AM的系统,该系统直接将RSS值用作检测参数。使用出边界帧的比率有助于检测高速率攻击。此外,我们建议对合法RSS值进行自适应学习,以增强攻击检测器针对环境变化的鲁棒性。使用幅度和频率相关功能,我们通过单个AM获得了很高的检测性能;这样就可以开发出针对欺骗攻击的预防措施。我们通过办公室环境中的IEEE 802.15.4测试平台评估了我们方法的性能。实验结果和理论分析表明,该方法优于现有的基于RSS的欺骗检测解决方案。使用单个AM,我们能够达到94.75%的检测率(DR)和0.56%的假阳性率(FPR)。对于4 AM,结果提高到了99%的DR和0%的FPR。

著录项

  • 来源
    《Ad hoc networks》 |2013年第8期|2648-2660|共13页
  • 作者单位

    Department of Electrical and Computer Engineering, The University of British Columbia, Vancouver, BC, Canada V6T 1Z4;

    Department of Electrical and Computer Engineering, The University of British Columbia, Vancouver, BC, Canada V6T 1Z4;

    Department of Electrical and Computer Engineering, The University of British Columbia, Vancouver, BC, Canada V6T 1Z4;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Spoofing; IDS; IEEE 802.15.4;

    机译:欺骗;IDS;IEEE 802.15.4;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号