Title :
On Achieving Cost-Sensitive Anomaly Detection and Response in Mobile Ad Hoc Networks
Author :
Zhang, Zonghua ; Ho, Pin-Han ; Naït-Abdesselam, Farid
Author_Institution :
SRC-TBN, NICT, Japan
Abstract :
In Mobile Ad Hoc Networks (MANET), anomaly detection and response system (ADRS) plays a paramount role in diagnosing anomalous events, which are resulted by both accidental system errors and intentional attacks. While a variety of ADRS is ready for deployment, there lacks a sound and formal way to examine their operational characteristics for selecting the most appropriate ones with particular concerns. To that end, this paper develops a decision-theoretical framework to identify the fundamental tradeoffs between the key evaluation metrics of ADRS in MANET, along with a formal method to optimize the overall performance of ADRS in terms of those metrics of concern. In particular, each ADRS sensor is treated as an autonomous agent, making its decision as the local operational environment and a global signal that estimates the performance of ADRS as a whole, in terms of detection performance (detection accuracy and false positive rate) and operational cost (detection cost and response cost). The theoretical framework then serves as a basis for developing policy gradient algorithms for practically and automatically inferring the optimal behavior of ADRS sensors. A set of simulations is conducted for validating the feasibility and evaluating the performance of our proposed framework.
Keywords :
ad hoc networks; mobile radio; telecommunication security; ADRS sensor; MANET; accidental system errors; anomalous events; autonomous agent; cost-sensitive anomaly detection; decision-theoretical framework; detection accuracy; detection cost; detection performance; false positive rate; intentional attacks; key evaluation metrics; mobile ad hoc networks; operational cost; policy gradient algorithms; response cost; response system; Autonomous agents; Communications Society; Cost function; Event detection; Humans; Impedance; Intrusion detection; Measurement; Mobile ad hoc networks; Optimization methods;
Conference_Titel :
Communications, 2009. ICC '09. IEEE International Conference on
Conference_Location :
Dresden
Print_ISBN :
978-1-4244-3435-0
Electronic_ISBN :
1938-1883
DOI :
10.1109/ICC.2009.5199233