Title :
Detecting coordinated attacks in tactical wireless networks using cooperative signature-based detectors
Author :
Little, Mike ; Ko, Calvin
Author_Institution :
Telcordia Technol., Inc, Morristown, NJ
Abstract :
We describe an approach to detecting coordinated attacks in tactical wireless networks in which distributed detectors cooperate to match signatures from audit events generated at different locations. Traditionally, the signature matching engine compares the signature with a single audit data stream to identify occurrences of the action sequence described in the signature. Such approach introduces a single point of failure and uses huge bandwidth for transferring audit data from the data sources to the matching engine. Our approach decomposes an extended infinite state machine, an operational representation of an attack signature, into multiple cooperative finite state machines that enable distributed signature engines to match the signature. We describe the decomposition methodology and the distributed matching algorithm and illustrate them using several example multi-stage attacks in tactical networks. In addition, we implemented an example distributed signature matching engine for detecting the example attacks in a simulation framework based on MASON. Our approach avoids a single point of failure and reduces the bandwidth usage by communicating internal state information rather than audit events
Keywords :
finite state machines; military communication; telecommunication security; wireless sensor networks; MASON; attack signature; cooperative signature-based detectors; coordinated attacks detection; extended infinite state machine; internal state information; multistage attacks; signature matching engine; single audit data stream; tactical wireless networks; Bandwidth; Collaboration; Detectors; Engines; Event detection; Government; Intelligent networks; Intrusion detection; Mobile communication; Wireless networks;
Conference_Titel :
Military Communications Conference, 2005. MILCOM 2005. IEEE
Conference_Location :
Atlantic City, NJ
Print_ISBN :
0-7803-9393-7
DOI :
10.1109/MILCOM.2005.1605682