Title :
Securing the 802.11 MAC in MANETs: A specification-based intrusion detection engine
Author :
Panos, Christoforos ; Kotzias, Platon ; Xenakis, Christos ; Stavrakakis, Ioannis
Author_Institution :
Dept. of Inf. & Telecommun., Univ. of Athens, Athens, Greece
Abstract :
Specification-based detection engines share the advantages of signature-based and anomaly-based detection, since they can detect unknown attacks, without the side effects of high rates of false positives. However, such solutions for MANETs have seen limited use. This paper introduces a specification-based detection engine that is built upon the functionality and limitations of the 802.11 MAC protocol, expanding the detection range of such engines in MANETs. The proposed detection engine is deployed at each node and performs detection using a set of specifications, which describe the correct operation of the MAC protocol operating at the host node. The proposed engine introduces a number of significant advantages since it can effectively detect both known and unknown attacks in real time and with minimum overhead. Moreover, it is resilient to the dynamic topologies that are common in MANETs and its deployment requires no protocol modifications.
Keywords :
access protocols; mobile ad hoc networks; telecommunication network topology; telecommunication security; wireless LAN; IEEE802.11 MAC protocol security; MANET; anomaly-based detection; dynamic topology; host node; signature-based detection; specification-based intrusion detection engine; Ad hoc networks; Engines; IEEE 802.11 Standards; Media Access Protocol; Mobile computing; Monitoring; 802.11 vulnerabilities; IDS; MANET security; data-link layer attacks; intrusion detection system; mobile ad hoc networks; security vulnerabilities; specification-based intrusion detection engine;
Conference_Titel :
Wireless On-demand Network Systems and Services (WONS), 2012 9th Annual Conference on
Conference_Location :
Courmayeur
Print_ISBN :
978-1-4577-1721-5
Electronic_ISBN :
978-1-4577-1720-8
DOI :
10.1109/WONS.2012.6152225