DocumentCode
3391270
Title
Detecting coordinated attacks in tactical wireless networks using cooperative signature-based detectors
Author
Little, Mike ; Ko, Calvin
Author_Institution
Telcordia Technol., Inc, Morristown, NJ
fYear
2005
fDate
17-20 Oct. 2005
Firstpage
176
Abstract
We describe an approach to detecting coordinated attacks in tactical wireless networks in which distributed detectors cooperate to match signatures from audit events generated at different locations. Traditionally, the signature matching engine compares the signature with a single audit data stream to identify occurrences of the action sequence described in the signature. Such approach introduces a single point of failure and uses huge bandwidth for transferring audit data from the data sources to the matching engine. Our approach decomposes an extended infinite state machine, an operational representation of an attack signature, into multiple cooperative finite state machines that enable distributed signature engines to match the signature. We describe the decomposition methodology and the distributed matching algorithm and illustrate them using several example multi-stage attacks in tactical networks. In addition, we implemented an example distributed signature matching engine for detecting the example attacks in a simulation framework based on MASON. Our approach avoids a single point of failure and reduces the bandwidth usage by communicating internal state information rather than audit events
Keywords
finite state machines; military communication; telecommunication security; wireless sensor networks; MASON; attack signature; cooperative signature-based detectors; coordinated attacks detection; extended infinite state machine; internal state information; multistage attacks; signature matching engine; single audit data stream; tactical wireless networks; Bandwidth; Collaboration; Detectors; Engines; Event detection; Government; Intelligent networks; Intrusion detection; Mobile communication; Wireless networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Military Communications Conference, 2005. MILCOM 2005. IEEE
Conference_Location
Atlantic City, NJ
Print_ISBN
0-7803-9393-7
Type
conf
DOI
10.1109/MILCOM.2005.1605682
Filename
1605682
Link To Document