DocumentCode
2588075
Title
ARSoS: An Adaptive, Robust, and Sub-Optimal Strategy for Automated Deployment of Anomaly Detection System in MANETs
Author
Zhang, Zonghua ; Nait-Abdesselam, Farid ; Djahel, Soufiene
Author_Institution
LIFL, Univ. of Sci. & Technol. of Lille, Lille
fYear
2008
fDate
6-8 Aug. 2008
Firstpage
606
Lastpage
613
Abstract
While a variety of AIDS (anomaly-based intrusion detection system) are claimed to be fully distributed, lightweight, and ready for application, their detection cost are not always neglectable, especially when considering the fact that MANET nodes have scarce resources which usually impels them to avoid any unnecessary action. It is therefore a significant issue to optimally deploy AIDS sensors to achieve a better tradeoff between performance and detection cost. However, this optimization problem is challenging in essence because of the special characteristics of MANETs. In particular, the deployment strategy must be adaptive to capture nodes´ mobility and robust to detection failures resulted from either accidental system error or intentional subversion. In this paper, we propose an adaptive, robust, and sub-optimal strategy, called ARSoS, to tackle this issue. ARSoS treats each AIDS sensor as an independent agent, and then formulates the sensors´ cooperative behavior as a decentralized decision problem. Since each AIDS sensor is only aware of partial information about the other sensors and the neighboring nodes, a reward signal integrating both local observations and global detection measures is introduced to guide the overall cooperation of sensors. An online policy gradient algorithm is then applied to solve the formulated problem. To validate the ARSoS system in terms of adaptability, robustness and optimality, we conducted extensive simulations of an implemented prototype and the obtained results highlight a good performance of the system.
Keywords
ad hoc networks; mobile radio; security of data; telecommunication security; AIDS sensor; ARSoS; MANET; adaptive strategy; anomaly detection system; anomaly-based intrusion detection system; decentralized decision problem; global detection measures; local observations; mobile ad-hoc networks; online policy gradient algorithm; optimization problem; robust strategy; sub-optimal strategy; Acoustic sensors; Acquired immune deficiency syndrome; Computational modeling; Cost function; Intrusion detection; Mobile ad hoc networks; Noise robustness; Sensor phenomena and characterization; Virtual prototyping; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Wireless Communications and Mobile Computing Conference, 2008. IWCMC '08. International
Conference_Location
Crete Island
Print_ISBN
978-1-4244-2201-2
Electronic_ISBN
978-1-4244-2202-9
Type
conf
DOI
10.1109/IWCMC.2008.105
Filename
4600004
Link To Document