首页> 外文期刊>Information management & computer security >An efficient intrusion detection and prevention framework for ad hoc networks
【24h】

An efficient intrusion detection and prevention framework for ad hoc networks

机译:Ad hoc网络的有效入侵检测和预防框架

获取原文
获取原文并翻译 | 示例

摘要

Purpose - Wireless multi-hop ad hoc networks are becoming very attractive and widely deployed in many kinds of communication and networking applications. However, distributed and collaborative routing in such networks makes them vulnerable to various security attacks. This paper aims to design and implement a new efficient intrusion detection and prevention framework, called EIDPF, a host-based framework suitable for mobile ad hoc network's characteristics such as high node's mobility, resource-constraints and rapid topology change. EIDPF aims to protect an AODV-based network against routing attacks that could target such network. Design/methodology/approach - This detection and prevention framework is composed of three complementary modules: a specification-based intrusion detection system to detect attacks violating the protocol specification, a load balancer to prevent fast-forwarding attacks such as wormhole and rushing and adaptive response mechanism to isolate malicious node from the network. Findings-A key advantage of the proposed framework is its capacity to efficiently avoid fast-forwarding attacks and its real-time detection of both known and unknown attacks violating specification. The simulation results show that EIDPF exhibits a high detection rate, low false positive rate and no extra communication overhead compared to other protection mechanisms. Originality/value - It is a new intrusion detection and prevention framework to protect ad hoc network against routing attacks. A key strength of the proposed framework is its ability to guarantee a real-time detection of known and unknown attacks that violate the protocol specification, and avoiding wormhole and rushing attacks by providing a load balancing route discovery.
机译:目的-无线多跳自组织网络变得越来越有吸引力,并广泛部署在许多类型的通信和网络应用中。但是,此类网络中的分布式协作路由使它们容易受到各种安全攻击。本文旨在设计和实现一种新的高效入侵检测和防御框架,称为EIDPF,这是一种基于主机的框架,适用于移动自组织网络的特征,例如高节点的移动性,资源约束和快速的拓扑变化。 EIDPF旨在保护基于AODV的网络免受可能针对此类网络的路由攻击。设计/方法/方法-此检测和预防框架由三个互补模块组成:一个基于规范的入侵检测系统,用于检测违反协议规范的攻击;一个负载均衡器,用于防止诸如蠕虫漏洞和紧急响应之类的快速转发攻击和自适应响应隔离恶意节点与网络的机制。结果-提出的框架的主要优势在于其有效避免快速转发攻击的能力以及对违反规范的已知和未知攻击的实时检测。仿真结果表明,与其他保护机制相比,EIDPF具有较高的检测率,较低的误报率和无额外的通信开销。原创性/价值-这是一个新的入侵检测和防御框架,可以保护ad hoc网络免受路由攻击。提出的框架的关键优势在于它能够确保实时检测到违反协议规范的已知和未知攻击,并通过提供负载平衡路由发现来避免虫洞和紧急攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号