• DocumentCode
    3712676
  • Title

    Anomaly-based intrusion detection of protocol-aware jamming

  • Author

    Marc Lichtman;Jeffrey H. Reed

  • Author_Institution
    Wireless @ Virginia Tech, United States of America
  • fYear
    2015
  • Firstpage
    269
  • Lastpage
    274
  • Abstract
    In this paper, we apply the existing framework of anomaly-based intrusion detection (ABID) to the problem of detecting protocol-aware jammers. These types of jammers target MAC or NET layer control messages in an attempt to increase jamming effectiveness and remain harder to detect. ABID systems detect activities that deviate significantly from the normal profile. Signature recognition is based on storing signatures of known intrusion scenarios, and detecting the presence of these signatures in real-time. By choosing a suitable set of features, a high probability of correct detection can be achieved. Our proposed detection strategy involves tracking the statistics of signal-to-noise ratio (SNR) and packet type (critical or non-critical). An alternative strategy that only requires information about packet loss is also provided. Through simulation, we show that these types of jammers can be detected in a large portion of scenarios.
  • Keywords
    "Jamming","Signal to noise ratio","Intrusion detection","Engines","Feature extraction","Physical layer","Analytical models"
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, MILCOM 2015 - 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/MILCOM.2015.7357454
  • Filename
    7357454