• DocumentCode
    1941145
  • Title

    A fully distributed IDS for MANET

  • Author

    Puttini, Ricardo ; Percher, Jean-Marc ; Mé, Ludovic ; De Sousa, Rafael

  • Author_Institution
    Brasilia Univ., Brazil
  • Volume
    1
  • fYear
    2004
  • fDate
    28 June-1 July 2004
  • Firstpage
    331
  • Abstract
    In This work we propose a new distributed intrusion detection system (IDS) designed for mobile ad hoc network (MANET) environments. The complete distribution of the intrusion detection process is the salient feature of our proposition: distribution is not restricted to data collection but also applied to execution of the detection algorithm and alert correlation. Each node in the MANET runs a local IDS (LIDS) that cooperates with others LIDS. A mobile agent framework is used to preserve the autonomy of each LIDS while providing a flexible technique for exploring the natural redundancies in MANET to compensate for the dynamic state of wireless links between high mobility nodes. The proposed solution has been validated by actual implementation, which is described in the paper. Three attacks are presented as illustrative examples of the IDS mechanisms. Attack detection is formally described by specification of data collection, attack signatures associated with such data and alerts generation and correlation. Experiments exhibit fairly good results, the attacks being collaboratively detected in real-time.
  • Keywords
    ad hoc networks; mobile agents; mobile radio; security of data; MANET; attack detection; data collection; fully distributed IDS; intrusion detection system; mobile ad hoc network; mobile agent framework; Bandwidth; Collaboration; Detection algorithms; Dispatching; Information management; Intrusion detection; Mobile ad hoc networks; Mobile agents; Peer to peer computing; Routing protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2004. Proceedings. ISCC 2004. Ninth International Symposium on
  • Print_ISBN
    0-7803-8623-X
  • Type

    conf

  • DOI
    10.1109/ISCC.2004.1358426
  • Filename
    1358426