• DocumentCode
    2446510
  • Title

    Efficient data capturing for network forensics in cognitive radio networks

  • Author

    Chen, Shaxun ; Zeng, Kai ; Mohapatra, Prasant

  • Author_Institution
    Dept. of Comput. Sci., Univ. of California Davis, Davis, CA, USA
  • fYear
    2011
  • fDate
    17-20 Oct. 2011
  • Firstpage
    176
  • Lastpage
    185
  • Abstract
    Network forensics is widely used in tracking down criminals and detecting network anomalies, and data capture is the basis of network forensics. Compared to traditional networks, data capture faces significant challenges in cognitive radio networks. In traditional wireless networks, one monitor is usually assigned to one channel to capture traffic, which incurs very high cost in a cognitive radio network because the latter typically has a large number of channels. Furthermore, due to the uncertainty of the primary user´s activity, cognitive radio devices change their operating channels randomly, which makes data capturing more difficult. In this paper, we propose a systematic method to capture data in cognitive radio networks with a small number of monitors. We utilize incremental support vector regression to predict packet arrival time and intelligently switch monitors between channels. In addition, a protocol is proposed to schedule multiple monitors to perform channel scan and packet capturing in an efficient manner. The real-world experiments and simulations show that our method is able to achieve the packet capture rate above 70% using a small number of monitors, which outperforms the random scheme by 200%-300%.
  • Keywords
    cognitive radio; computer forensics; computer networks; radio networks; regression analysis; support vector machines; cognitive radio networks; efficient data capture; incremental support vector regression; network anomaly detection; network forensics; packet arrival time; wireless network; Cognitive radio; Forensics; Monitoring; Prediction algorithms; Support vector machines; Switches; Training;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2011 19th IEEE International Conference on
  • Conference_Location
    Vancouver, BC
  • Print_ISBN
    978-1-4577-1392-7
  • Type

    conf

  • DOI
    10.1109/ICNP.2011.6089049
  • Filename
    6089049