首页> 外文期刊>Computers & Security >A comparative evaluation of intrusion detection architectures for mobile ad hoc networks
【24h】

A comparative evaluation of intrusion detection architectures for mobile ad hoc networks

机译:移动自组织网络入侵检测体系结构的比较评估

获取原文
获取原文并翻译 | 示例
           

摘要

Mobile Ad Hoc Networks (MANETs) are susceptible to a variety of attacks that threaten their operation and the provided services. Intrusion Detection Systems (IDSs) may act as defensive mechanisms, since they monitor network activities in order to detect malicious actions performed by intruders, and then initiate the appropriate countermeasures. IDS for MANETs have attracted much attention recently and thus, there are many publications that propose new IDS solutions or improvements to the existing. This paper evaluates and compares the most prominent IDS architectures for MANETs. IDS architectures are defined as the operational structures of IDSs. For each IDS, the architecture and the related functionality are briefly presented and analyzed focusing on both the operational strengths and weaknesses. Moreover, methods/techniques that have been proposed to improve the performance and the provided security services of those are evaluated and their shortcomings or weaknesses are presented. A comparison of the studied IDS architectures is carried out using a set of critical evaluation metrics, which derive from: (i) the deployment, architectural, and operational characteristics of MANETs; (ii) the special requirements of intrusion detection in MANETs; and (iii) the carried analysis that reveals the most important strengths and weaknesses of the existing IDS architectures. The evaluation metrics of IDSs are divided into two groups: the first one is related to performance and the second to security. Finally, based on the carried evaluation and comparison a set of design features and principles are presented, which have to be addressed and satisfied in future research of designing and implementing IDSs for MANETs.
机译:移动自组织网络(MANET)容易受到各种攻击的威胁,这些攻击会威胁其运行和提供的服务。入侵检测系统(IDS)可以充当防御机制,因为它们监视网络活动以检测入侵者执行的恶意行为,然后启动适当的对策。用于MANET的IDS最近引起了很多关注,因此,许多出版物提出了新的IDS解决方案或对现有IDS解决方案的改进。本文评估并比较了用于MANET的最杰出的IDS体系结构。 IDS体系结构被定义为IDS的操作结构。对于每个IDS,简要介绍并分析了体系结构和相关功能,并着重于操作优势和劣势。此外,评估了已提出的改善性能和提供的安全服务的方法/技术,并提出了它们的缺点或弱点。使用一组关键评估指标对研究的IDS架构进行比较,这些指标来自:(i)MANET的部署,架构和操作特性; (ii)MANET中入侵检测的特殊要求; (iii)进行的分析揭示了现有IDS体系结构最重要的优点和缺点。 IDS的评估指标分为两类:第一个与性能有关,第二个与安全有关。最后,在进行评估和比较的基础上,提出了一组设计特征和原理,这些特征和原理在未来针对MANET的IDS的设计和实现研究中必须得到解决和满足。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号