• DocumentCode
    3311049
  • Title

    Forensic analysis of packet losses in wireless networks

  • Author

    Jianxia Ning ; Singh, Sushil ; Pelechrinis, Konstantinos ; Liu, B. ; Krishnamurthy, Srikanth V. ; Govindan, Ramesh

  • Author_Institution
    Univ. of California, Riverside, Riverside, CA, USA
  • fYear
    2012
  • fDate
    Oct. 30 2012-Nov. 2 2012
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Due to the lossy nature of wireless links, it is difficult to determine if packet losses are due to wireless-induced effects or from malicious discarding. Many prior efforts on detecting malicious packet drops rely on evidence collected via passive monitoring by neighbor nodes; however, they do not analyze the cause of packet losses. In this paper, we ask: (a) Given certain macroscopic parameters of the network (like traffic intensity and node density) what is the likelihood that evidence exists with respect to a transmission? and, (b) How can these parameters be used to perform a forensic analysis of the reason for the losses? Towards answering the above questions, we first build an analytical framework that computes the likelihood that evidence (we call this transmission evidence or TE for short) exists with respect to transmissions, in terms of a set of network parameters. We validate our analytical framework via both simulations as well as real-world experiments on two different wireless testbeds. The analytical framework is then used as a basis for a protocol within a forensic analyzer to assess the cause of packet losses and determine the likelihood of forwarding misbehaviors. Through simulations, we find that our assessments are close to the ground truth in all examined cases, with an average deviation of 2.3% from the ground truth and a worst case deviation of 15.0%.
  • Keywords
    radio links; radio networks; telecommunication traffic; forensic analysis; malicious packet drops detection; node density; packet losses; traffic intensity; transmission evidence; wireless links; wireless networks; Availability; Forensics; Interference; Packet loss; Receivers; Transmitters;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2012 20th IEEE International Conference on
  • Conference_Location
    Austin, TX
  • Print_ISBN
    978-1-4673-2445-8
  • Electronic_ISBN
    978-1-4673-2446-5
  • Type

    conf

  • DOI
    10.1109/ICNP.2012.6459972
  • Filename
    6459972