• DocumentCode
    1675897
  • Title

    An Analysis of Monitoring Based Intrusion Detection for Ad Hoc Networks

  • Author

    Boppana, Rajendra V. ; Su, Xu

  • Author_Institution
    Comput. Sci. Dept., UT San Antonio, San Antonio, TX
  • fYear
    2008
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Several intrusion detection techniques proposed for mobile ad hoc networks rely on each node passively monitoring the data forwarding by its next hop. This paper presents quantitative evaluations of false positives and their impact on monitoring based intrusion detection for ad hoc networks. Experimental results show that even for a simple 3-node configuration, an actual ad hoc network suffers from high false positives; these results are validated by a Markov model. However, this false positive problem cannot be observed by simulating the same network using popular ad hoc network simulators such as ns- 2, OPNET or Glomosim with default noise models. To remedy this, a probabilistic noise generator model is incorporated in the Glomosim simulator. With this revised noise model, the simulated network exhibits the aggregate false positive behavior similar to that of the experimental testbed. Simulations of larger (50- node) ad hoc networks indicate that a monitoring based intrusion detection has very high false positives which impact its ability to mitigate the attacks.
  • Keywords
    ad hoc networks; mobile radio; noise generators; Markov model; data forwarding; intrusion detection; mobile ad hoc networks; probabilistic noise generator; Ad hoc networks; Computer science; Computerized monitoring; Intrusion detection; Military computing; Mobile ad hoc networks; Noise level; Power system security; Testing; Working environment noise;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE
  • Conference_Location
    New Orleans, LO
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4244-2324-8
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2008.ECP.402
  • Filename
    4698177