• DocumentCode
    2858079
  • Title

    A general cooperative intrusion detection architecture for MANETs

  • Author

    Sterne, D. ; Carman, D. ; Wilson, Brian ; Talpade, R. ; Ko, Chun-Han ; Tseng, Chen-Yu ; Bowen, Terry

  • Author_Institution
    McAfee Res., Santa Clara, CA, USA
  • fYear
    2005
  • fDate
    23-24 March 2005
  • Firstpage
    57
  • Lastpage
    70
  • Abstract
    Intrusion detection in MANETs is challenging because these networks change their topologies dynamically; lack concentration points where aggregated traffic can be analyzed; utilize infrastructure protocols that are susceptible to manipulation; and rely on noisy, intermittent wireless communications. We present a cooperative, distributed intrusion detection architecture that addresses these challenges while facilitating accurate detection of MANET-specific and conventional attacks. The architecture is organized as a dynamic hierarchy in which detection data is acquired at the leaves and is incrementally aggregated, reduced, and analyzed as it flows upward toward the root. Security management directives flow downward from nodes at the top. To maintain communications efficiency, the hierarchy is automatically reconfigured as needed using clustering techniques in which clusterheads are selected based on topology and other criteria. The utility of the architecture is illustrated via multiple attack scenarios.
  • Keywords
    ad hoc networks; groupware; mobile computing; mobile radio; protocols; security of data; telecommunication network management; telecommunication network topology; telecommunication security; telecommunication traffic; MANET; automatic reconfiguration; clusterheads; clustering techniques; cooperative intrusion detection architecture; detection data acquisition; distributed intrusion detection architecture; infrastructure protocols; mobile ad hoc networks; network topology; security management; wireless communications; Collaboration; Intrusion detection; Military computing; Mobile ad hoc networks; Mobile communication; Network topology; Routing protocols; Telecommunication traffic; Wireless application protocol; Wireless communication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
  • Print_ISBN
    0-7695-2317-X
  • Type

    conf

  • DOI
    10.1109/IWIA.2005.1
  • Filename
    1410702