• DocumentCode
    3391270
  • Title

    Detecting coordinated attacks in tactical wireless networks using cooperative signature-based detectors

  • Author

    Little, Mike ; Ko, Calvin

  • Author_Institution
    Telcordia Technol., Inc, Morristown, NJ
  • fYear
    2005
  • fDate
    17-20 Oct. 2005
  • Firstpage
    176
  • Abstract
    We describe an approach to detecting coordinated attacks in tactical wireless networks in which distributed detectors cooperate to match signatures from audit events generated at different locations. Traditionally, the signature matching engine compares the signature with a single audit data stream to identify occurrences of the action sequence described in the signature. Such approach introduces a single point of failure and uses huge bandwidth for transferring audit data from the data sources to the matching engine. Our approach decomposes an extended infinite state machine, an operational representation of an attack signature, into multiple cooperative finite state machines that enable distributed signature engines to match the signature. We describe the decomposition methodology and the distributed matching algorithm and illustrate them using several example multi-stage attacks in tactical networks. In addition, we implemented an example distributed signature matching engine for detecting the example attacks in a simulation framework based on MASON. Our approach avoids a single point of failure and reduces the bandwidth usage by communicating internal state information rather than audit events
  • Keywords
    finite state machines; military communication; telecommunication security; wireless sensor networks; MASON; attack signature; cooperative signature-based detectors; coordinated attacks detection; extended infinite state machine; internal state information; multistage attacks; signature matching engine; single audit data stream; tactical wireless networks; Bandwidth; Collaboration; Detectors; Engines; Event detection; Government; Intelligent networks; Intrusion detection; Mobile communication; Wireless networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2005. MILCOM 2005. IEEE
  • Conference_Location
    Atlantic City, NJ
  • Print_ISBN
    0-7803-9393-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2005.1605682
  • Filename
    1605682