• DocumentCode
    496902
  • Title

    On Achieving Cost-Sensitive Anomaly Detection and Response in Mobile Ad Hoc Networks

  • Author

    Zhang, Zonghua ; Ho, Pin-Han ; Naït-Abdesselam, Farid

  • Author_Institution
    SRC-TBN, NICT, Japan
  • fYear
    2009
  • fDate
    14-18 June 2009
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    In Mobile Ad Hoc Networks (MANET), anomaly detection and response system (ADRS) plays a paramount role in diagnosing anomalous events, which are resulted by both accidental system errors and intentional attacks. While a variety of ADRS is ready for deployment, there lacks a sound and formal way to examine their operational characteristics for selecting the most appropriate ones with particular concerns. To that end, this paper develops a decision-theoretical framework to identify the fundamental tradeoffs between the key evaluation metrics of ADRS in MANET, along with a formal method to optimize the overall performance of ADRS in terms of those metrics of concern. In particular, each ADRS sensor is treated as an autonomous agent, making its decision as the local operational environment and a global signal that estimates the performance of ADRS as a whole, in terms of detection performance (detection accuracy and false positive rate) and operational cost (detection cost and response cost). The theoretical framework then serves as a basis for developing policy gradient algorithms for practically and automatically inferring the optimal behavior of ADRS sensors. A set of simulations is conducted for validating the feasibility and evaluating the performance of our proposed framework.
  • Keywords
    ad hoc networks; mobile radio; telecommunication security; ADRS sensor; MANET; accidental system errors; anomalous events; autonomous agent; cost-sensitive anomaly detection; decision-theoretical framework; detection accuracy; detection cost; detection performance; false positive rate; intentional attacks; key evaluation metrics; mobile ad hoc networks; operational cost; policy gradient algorithms; response cost; response system; Autonomous agents; Communications Society; Cost function; Event detection; Humans; Impedance; Intrusion detection; Measurement; Mobile ad hoc networks; Optimization methods;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2009. ICC '09. IEEE International Conference on
  • Conference_Location
    Dresden
  • ISSN
    1938-1883
  • Print_ISBN
    978-1-4244-3435-0
  • Electronic_ISBN
    1938-1883
  • Type

    conf

  • DOI
    10.1109/ICC.2009.5199233
  • Filename
    5199233