• DocumentCode
    3503671
  • Title

    Cross-feature analysis for detecting ad-hoc routing anomalies

  • Author

    Huang, Yi-an ; Fan, Wei ; Lee, Wenke ; Yu, Philip S.

  • Author_Institution
    Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2003
  • fDate
    19-22 May 2003
  • Firstpage
    478
  • Lastpage
    487
  • Abstract
    With the proliferation of wireless devices, mobile ad-hoc networking (MANET) has become a very exciting and important technology. However, MANET is more vulnerable than wired networking. Existing security mechanisms designed for wired networks have to be redesigned in this new environment. In this paper, we discuss the problem of intrusion detection in MANET. The focus of our research is on techniques for automatically constructing anomaly detection models that are capable of detecting new (or unseen) attacks. We introduce a new data mining method that performs "cross-feature analysis" to capture the inter-feature correlation patterns in normal traffic. These patterns can be used as normal profiles to detect deviation (or anomalies) caused by attacks. We have implemented our method on a few well known ad-hoc routing protocols, namely, Dynamic Source Routing (DSR) and Ad-hoc On-Demand Distance Vector (AODV), and have conducted extensive experiments on the ns-2 simulator. The results show that the anomaly detection models automatically computed using our data mining method can effectively, detect anomalies caused by typical routing intrusions.
  • Keywords
    ad hoc networks; data mining; mobile computing; routing protocols; telecommunication security; MANET; ad hoc routing anomaly detection model; ad-hoc on-demand distance vector; cross-feature analysis; data mining; dynamic source routing; intrusion detection; mobile ad-hoc networking; routing protocol; Communication system security; Computer networks; Cryptography; Data mining; Data security; Educational institutions; Intrusion detection; Mobile ad hoc networks; Mobile computing; Routing protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems, 2003. Proceedings. 23rd International Conference on
  • ISSN
    1063-6927
  • Print_ISBN
    0-7695-1920-2
  • Type

    conf

  • DOI
    10.1109/ICDCS.2003.1203498
  • Filename
    1203498