计算机科学 ›› 2009, Vol. 36 ›› Issue (11): 75-78.

• 计算机网络与信息安全 • 上一篇    下一篇

无线自组织网络中多层综合的节点行为异常检测方法

王涛,余顺争   

  1. (中山大学信息科学与技术学院电子与通信工程系 广州510275)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家高技术研究发展计划(863计划)专题课题(2007AA01Z449)及国家自然科学基金-广东联合基金重点项目(U0735002)资助。

Multi-layer Integrated Anomaly Detection of Mobile Nodes Behaviors in Mobile Ad Hoc Networks

WANG Tao YU Shun-zheng   

  • Online:2018-11-16 Published:2018-11-16

摘要: Ad hoc网络由于采用无线信道、有限的电源和带宽、分布式控制等,会比有线网络更易受到入侵攻击。通常的入侵检测技术具有检测能力单一、缺乏对杭新入侵方式的能力等缺陷。在分布式入侵检测系统(( IDS)的基础上,提出一种针对移动节点网络行为的异常检测机制。基于多层综合的观测值序列,采用隐半马尔可夫模型( HSMM)建立描述网络中合法节点正常行为的检测模型,继而对网络中的正常与异常行为进行判断与识别。实验表明,此方法能针对现有多种入侵方式进行有效的检测。

关键词: Ad hoc网络,入侵检测系统,异常检测,隐半马尔可夫模型

Abstract: Mobile Ad hoc Networks arc very vulnerable to malicious attacks due to the nature of mobile computing environment such as wireless communication channels, limited power and bandwidth, dynamically changing and distributed network topology,etc. The general existing Intrusion Detection Systems (IDS) have provided little evidence that they are applicable to a broader range threats. Based on the generalized and cooperative intrusion detection architecture proposed as the foundation for all intrusion detection, we presented an anomaly detection mechanism to discriminate the illegitimate network behaviors of mobile nodes. 13y collecting the observation sequences of multiple protocol layers, Hidden semi-Markov Model (HSMM) was explored to describe the network behaviors of legitimate nodes and to implement the anomaly detection for various malicious attacks. We conducted extensive experiments using the ns-2 simulation environment to evaluate and validate our research.

Key words: Mobile ad hoc network, IDS, Anomaly detection, HSMM

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!