DocumentCode :
2342917
Title :
CAPTRA: coordinated packet traceback
Author :
Sy, Denh ; Bao, Lichun
Author_Institution :
Bren Sch. of Inf. & Comput. Sci., California Univ., Irvine, CA
fYear :
0
fDate :
0-0 0
Firstpage :
152
Lastpage :
159
Abstract :
Network-based attacks can be either persistent or sporadic. Persistent attack flows can be relatively easy to trace by mechanisms such as probabilistic packet marking, traffic logging, data mining etc. Sporadic attacks are sometimes easily detected by the intrusion detection systems (IDSs) at the victims, but are hard to trace back to the attack origins. We propose CAPTRA, a coordinated packet traceback mechanism, for wireless sensor networks (WSNs) that takes advantage of the broadcasting nature of the packet transmissions. By remembering packets in multi-dimensional Bloom filters distributed in overhearing sensors and later retrieving the information, CAPTRA identifies the path of the packet transfers using a series of REQUEST-VERDICT-CONFESS message exchanges between the forwarding and overhearing nodes. CAPTRA requires only small memory footprint on the sensors due to the usage of Bloom filters, and allows sensors to asynchronously refresh the Bloom filters so that the network traffic is continuously monitored. CAPTRA is simulated using J-Sim, and a few key parameters are tuned for the best tracing performance
Keywords :
broadcasting; filters; information retrieval; packet radio networks; telecommunication security; telecommunication traffic; wireless sensor networks; CAPTRA; IDS; REQUEST-VERDICT-CONFESS message; WSN; broadcasting; coordinated packet traceback mechanism; information retrieval; intrusion detection system; multidimensional Bloom filter; network traffic; packet transmission; persistent attack; sporadic attack; wireless sensor network; Broadcasting; Data mining; Information filtering; Information filters; Information retrieval; Intrusion detection; Monitoring; Telecommunication traffic; Traffic control; Wireless sensor networks; Bloom filter; Wireless sensor networks; packet traceback;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Processing in Sensor Networks, 2006. IPSN 2006. The Fifth International Conference on
Conference_Location :
Nashville, TN
Print_ISBN :
1-59593-334-4
Type :
conf
DOI :
10.1109/IPSN.2006.244130
Filename :
1662453
Link To Document :
بازگشت