DocumentCode :
122515
Title :
Making active-probing-based network intrusion detection in Wireless Multihop Networks practical: A Bayesian inference approach to probe selection
Author :
do Carmo, Rodrigo ; Hoffmann, J. ; Willert, Volker ; Hollick, M.
Author_Institution :
Secure Mobile Networking Lab., Tech. Univ. Darmstadt, Darmstadt, Germany
fYear :
2014
fDate :
8-11 Sept. 2014
Firstpage :
345
Lastpage :
353
Abstract :
Practical intrusion detection in Wireless Multihop Networks (WMNs) is a hard challenge. The distributed nature of the network makes centralized intrusion detection difficult, while resource constraints of the nodes and the characteristics of the wireless medium often render decentralized, node-based approaches impractical. We demonstrate that an active-probing-based network intrusion detection system (AP-NIDS) is practical for WMNs. The key contribution of this paper is to optimize the active probing process: we introduce a general Bayesian model and design a probe selection algorithm that reduces the number of probes while maximizing the insights gathered by the AP-NIDS. We validate our model by means of testbed experimentation. We integrate it to our open source AP-NIDS DogoIDS and run it in an indoor wireless mesh testbed utilizing the IEEE 802.11s protocol. For the example of a selective packet dropping attack, we develop the detection states for our Bayes model, and show its feasibility. We demonstrate that our approach does not need to execute the complete set of probes, yet we obtain good detection rates.
Keywords :
Bayes methods; indoor communication; security of data; telecommunication standards; wireless mesh networks; AP-NIDS DogoIDS; Bayesian inference; Bayesian model; IEEE 802.11s; WMN; active-probing-based network intrusion detection system; indoor wireless mesh testbed; probe selection algorithm; testbed experimentation; wireless multihop networks; Bayes methods; Equations; Intrusion detection; Probes; Spread spectrum communication; Testing; Wireless communication; Bayes inference; Intrusion Detection; Security; Wireless Multihop Networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Local Computer Networks (LCN), 2014 IEEE 39th Conference on
Conference_Location :
Edmonton, AB
Print_ISBN :
978-1-4799-3778-3
Type :
conf
DOI :
10.1109/LCN.2014.6925790
Filename :
6925790
Link To Document :
بازگشت