...
首页> 外文期刊>Computer Communications >A specification-based intrusion detection engine for infrastructure-less networks
【24h】

A specification-based intrusion detection engine for infrastructure-less networks

机译:基于规范的入侵检测引擎,用于无基础架构的网络

获取原文
获取原文并翻译 | 示例

摘要

The proliferation of mobile computing devices has enabled the utilization of infrastructure-less networking as commercial solutions. However, the distributed and cooperative nature of routing in such networks makes them vulnerable to a variety of attacks. This paper proposes a host-based monitoring mechanism, called SIDE that safeguards the operation of the AODV routing protocol. SIDE encompasses two complementary functionalities: (ⅰ) a specification-based detection engine for the AODV routing protocol, and (ⅱ) a remote attestation procedure that ensures the integrity of a running SIDE instance. The proposed mechanism operates on a trusted computing platform that provides hardware-based root of trust and cryptographic acceleration, used by the remote attestation procedure, as well as protection against runtime attacks. A key advantage of the proposed mechanism is its ability to effectively detect both known and unknown attacks, in real time. Performance analysis shows that attacks are resolved with high detection accuracy, even under conditions of high network volatility. Moreover, SIDE induces the least amount of control packet overhead in comparison with a number of other proposed IDS schemes.
机译:移动计算设备的激增已使无基础架构的网络成为商业解决方案。但是,此类网络中路由的分布式和协作性质使它们容易受到各种攻击。本文提出了一种基于主机的监视机制,称为SIDE,可以保护AODV路由协议的运行。 SIDE包含两个互补功能:(ⅰ)用于AODV路由协议的基于规范的检测引擎,以及(ⅱ)确保运行中的SIDE实例完整性的远程证明过程。所提出的机制在可信任的计算平台上运行,该平台可提供远程证明过程所使用的基于硬件的信任根和加密加速,以及针对运行时攻击的防护。所提出的机制的主要优势在于其能够实时有效检测已知和未知攻击的能力。性能分析表明,即使在网络波动很大的情况下,也能以较高的检测精度解决攻击。此外,与许多其他提议的IDS方案相比,SIDE导致最少的控制数据包开销。

著录项

  • 来源
    《Computer Communications》 |2014年第1期|67-83|共17页
  • 作者单位

    Department of Informatics & Telecommunications, University of Athens, Panepistimioupolis, Ilisia, 15784, Athens, Greece;

    Department of Digital Systems, University of Piraeus, 80 Karaoli & Dimitriou Street, 18534 Piraeus, Greece;

    Department of Digital Systems, University of Piraeus, 80 Karaoli & Dimitriou Street, 18534 Piraeus, Greece;

    Department of Informatics & Telecommunications, University of Athens, Panepistimioupolis, Ilisia, 15784, Athens, Greece;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    MANET; IDS; AODV; Detection engine; Attestation;

    机译:移动网IDS;AODV;检测引擎;证明书;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号