DocumentCode
2858079
Title
A general cooperative intrusion detection architecture for MANETs
Author
Sterne, D. ; Carman, D. ; Wilson, Brian ; Talpade, R. ; Ko, Chun-Han ; Tseng, Chen-Yu ; Bowen, Terry
Author_Institution
McAfee Res., Santa Clara, CA, USA
fYear
2005
fDate
23-24 March 2005
Firstpage
57
Lastpage
70
Abstract
Intrusion detection in MANETs is challenging because these networks change their topologies dynamically; lack concentration points where aggregated traffic can be analyzed; utilize infrastructure protocols that are susceptible to manipulation; and rely on noisy, intermittent wireless communications. We present a cooperative, distributed intrusion detection architecture that addresses these challenges while facilitating accurate detection of MANET-specific and conventional attacks. The architecture is organized as a dynamic hierarchy in which detection data is acquired at the leaves and is incrementally aggregated, reduced, and analyzed as it flows upward toward the root. Security management directives flow downward from nodes at the top. To maintain communications efficiency, the hierarchy is automatically reconfigured as needed using clustering techniques in which clusterheads are selected based on topology and other criteria. The utility of the architecture is illustrated via multiple attack scenarios.
Keywords
ad hoc networks; groupware; mobile computing; mobile radio; protocols; security of data; telecommunication network management; telecommunication network topology; telecommunication security; telecommunication traffic; MANET; automatic reconfiguration; clusterheads; clustering techniques; cooperative intrusion detection architecture; detection data acquisition; distributed intrusion detection architecture; infrastructure protocols; mobile ad hoc networks; network topology; security management; wireless communications; Collaboration; Intrusion detection; Military computing; Mobile ad hoc networks; Mobile communication; Network topology; Routing protocols; Telecommunication traffic; Wireless application protocol; Wireless communication;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
Print_ISBN
0-7695-2317-X
Type
conf
DOI
10.1109/IWIA.2005.1
Filename
1410702
Link To Document