• DocumentCode
    3405320
  • Title

    Detecting Wormhole Attacks in Mobile Ad Hoc Networks through Protocol Breaking and Packet Timing Analysis

  • Author

    Gorlatova, Maria A. ; Mason, Peter C. ; Wang, Maoyu ; Lamont, Louise ; Liscano, Ramiro

  • Author_Institution
    Commun. Res. Center, Ottawa Univ., Ont.
  • fYear
    2006
  • fDate
    23-25 Oct. 2006
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    We have implemented a fully-functional wormhole attack in an IPv6 802.11b wireless mobile ad hoc network (MANET) test bed running a proactive routing protocol. Using customised analysis tools we study the traffic collected from the MANET at three different stages: i) regular operation, ii) with a "benign" wormhole joining distant parts of the network, and iii) under stress from wormhole attackers who control a link in the MANET and drop packets at random. Our focus is on detecting anomalous behaviour using timing analysis of routing traffic within the network. We first show how to identify intruders based on the protocol irregularities that their presence creates once they begin to drop traffic. More significantly, we go on to demonstrate that the mere existence of the wormhole itself can be identified, before the intruders begin the packet-dropping phase of the attack, by applying simple signal-processing techniques to the arrival times of the routing management traffic. This is done by relying on a property of proactive routing protocols- that the stations must exchange management information on a specified, periodic basis. This exchange creates identifiable traffic patterns and an intrinsic "valid station" fingerprint that can be used for intrusion detection
  • Keywords
    IP networks; ad hoc networks; mobile radio; multiprocessor interconnection networks; routing protocols; security of data; signal processing; telecommunication traffic; IPv6 802.11b wireless MANET; customised analysis tools; intrusion detection; mobile ad hoc network; packet timing analysis; proactive routing protocol; routing management traffic; signal-processing technique; wormhole attack detection; Communication system traffic control; Fingerprint recognition; Information management; Intrusion detection; Mobile ad hoc networks; Routing protocols; Signal processing; Stress control; Testing; Timing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2006. MILCOM 2006. IEEE
  • Conference_Location
    Washington, DC
  • Print_ISBN
    1-4244-0617-X
  • Electronic_ISBN
    1-4244-0618-8
  • Type

    conf

  • DOI
    10.1109/MILCOM.2006.302162
  • Filename
    4086522