TY - GEN
T1 - Intrusion and anomaly detection model exchange for mobile ad-hoc networks
AU - Cretu, Gabriela F.
AU - Parekh, Janak J.
AU - Wang, Ke
AU - Stolfo, Salvatore J.
PY - 2006
Y1 - 2006
N2 - Mobile Ad-hoc NETworks (MANETs) pose unique security requirements and challenges due to their reliance on open, peer-to-peer models that often don't require authentication between nodes. Additionally, the limited processing power and battery life of the devices used in a MANET also prevent the adoption of heavy-duty cryptographic techniques. While traditional misuse-based Intrusion Detection Systems (IDSes) may work in a MANET, watching for packet dropouts or unknown outsiders is difficult as both occur frequently in both malicious and non-malicious traffic. Anomaly detection approaches hold out more promise, as they utilize learning techniques to adapt to the wireless environment and flag malicious data. The anomaly detection model can also create device behavior profiles, which peers can utilize to help determine its trustworthiness. However, computing the anomaly model itself is a time-consuming and processor-heavy task. To avoid this, we propose the use of model exchange as a device moves between different networks as a means to minimize computation and traffic utilization. Any node should be able to obtain peers' model(s) and evaluate it against its own model of "normal" behavior. We present this model, discuss scenarios in which it may be used, and provide preliminary results and a framework for future implementation.
AB - Mobile Ad-hoc NETworks (MANETs) pose unique security requirements and challenges due to their reliance on open, peer-to-peer models that often don't require authentication between nodes. Additionally, the limited processing power and battery life of the devices used in a MANET also prevent the adoption of heavy-duty cryptographic techniques. While traditional misuse-based Intrusion Detection Systems (IDSes) may work in a MANET, watching for packet dropouts or unknown outsiders is difficult as both occur frequently in both malicious and non-malicious traffic. Anomaly detection approaches hold out more promise, as they utilize learning techniques to adapt to the wireless environment and flag malicious data. The anomaly detection model can also create device behavior profiles, which peers can utilize to help determine its trustworthiness. However, computing the anomaly model itself is a time-consuming and processor-heavy task. To avoid this, we propose the use of model exchange as a device moves between different networks as a means to minimize computation and traffic utilization. Any node should be able to obtain peers' model(s) and evaluate it against its own model of "normal" behavior. We present this model, discuss scenarios in which it may be used, and provide preliminary results and a framework for future implementation.
KW - Anomaly detection
KW - Intrusion detection
KW - Mobile ad-hoc networks
KW - Model aggregation
KW - Model exchange
KW - Profiling
UR - https://www.scopus.com/pages/publications/33749060634
UR - https://www.scopus.com/pages/publications/33749060634#tab=citedBy
U2 - 10.1109/CCNC.2006.1593101
DO - 10.1109/CCNC.2006.1593101
M3 - Conference contribution
AN - SCOPUS:33749060634
SN - 1424400856
SN - 9781424400850
T3 - 2006 3rd IEEE Consumer Communications and Networking Conference, CCNC 2006
SP - 635
EP - 639
BT - 2006 3rd IEEE Consumer Communications and Networking Conference, CCNC 2006
T2 - 3rd IEEE Consumer Communications and Networking Conference, CCNC 2006
Y2 - 8 January 2006 through 10 January 2006
ER -