• DocumentCode
    2394566
  • Title

    A stochastic approximation approach for improving intrusion detection data fusion structures

  • Author

    Manousakis, K. ; Sterne, D. ; Ivanic, N. ; Lawler, G. ; McAuley, A.

  • Author_Institution
    Telcordia Technol., Piscataway, NJ, USA
  • fYear
    2008
  • fDate
    16-19 Nov. 2008
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    A variety of attacks on MANET routing, forwarding, and infrastructure protocols can only be detected using distributed cooperative algorithms. One promising strategy is to organize cooperative intrusion detection activities as a multiple-level intrusion detection (ID) hierarchy in which each node reports intrusion detection observations to its parent. This enables detection decisions to be based on aggregated data that has been gathered and consolidated from neighborhoods and larger network regions efficiently. A key challenge is the selection and maintenance of a scalable and robust hierarchy that optimizes detection performance (e.g., low latency, continuous coverage) while incurring minimal cost (e.g., bandwidth consumption). Existing approaches to constructing hierarchies in MANETs based on simple heuristics lack flexibility and cannot simultaneously address diverse performance and cost requirements. Moreover, mobility can produce constant large scale changes in the hierarchy that can degrade performance and increase cost. The main contributions of this paper are to: (a) identify ID structure design requirements and formulate them as objective functions and constraints, (b) adapt a multi-objective optimization framework to the formation of ID structures and, (c) provide indicative results concerning the quality of these structures with respect to the ID design requirements.
  • Keywords
    ad hoc networks; mobile radio; sensor fusion; telecommunication security; ID structure design requirements; MANET; intrusion detection data fusion structures; multi-objective optimization framework; Bandwidth; Cost function; Degradation; Delay; Intrusion detection; Large-scale systems; Mobile ad hoc networks; Robustness; Routing protocols; Stochastic processes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2008. MILCOM 2008. IEEE
  • Conference_Location
    San Diego, CA
  • Print_ISBN
    978-1-4244-2676-8
  • Electronic_ISBN
    978-1-4244-2677-5
  • Type

    conf

  • DOI
    10.1109/MILCOM.2008.4753175
  • Filename
    4753175