• DocumentCode
    835456
  • Title

    Control theoretic approach to intrusion detection using a distributed hidden Markov model

  • Author

    Khanna, Rahul ; Liu, Huaping

  • Author_Institution
    INTEL Corp., Santa Clara, CA
  • Volume
    15
  • Issue
    4
  • fYear
    2008
  • Firstpage
    24
  • Lastpage
    33
  • Abstract
    Cooperative ad hoc wireless networks are more vulnerable to malicious attacks than traditional wired networks. Many of these attacks are silent in nature and cannot be detected by conventional intrusion detection methods such as traffic monitoring, port scanning, or protocol violations. These sophisticated attacks operate under the threshold boundaries during an intrusion attempt and can only be identified by profiling the complete system activity in relation to normal behavior. In this article we discuss a control-theoretic hidden Markov model strategy for intrusion detection using distributed observation across multiple nodes. This model comprises a distributed HMM engine that executes in a randomly selected monitor node and functions as a part of the feedback control engine. This drives the defensive response based on hysteresis to reduce the frequency of false positives, thereby avoiding inappropriate ad hoc responses.
  • Keywords
    ad hoc networks; hidden Markov models; mobile radio; telecommunication control; telecommunication security; three-term control; cooperative ad hoc wireless network; distributed hidden Markov model; feedback control engine; intrusion detection; Communication system traffic control; Engines; Feedback control; Hidden Markov models; Hysteresis; Intrusion detection; Monitoring; Protocols; Traffic control; Wireless networks;
  • fLanguage
    English
  • Journal_Title
    Wireless Communications, IEEE
  • Publisher
    ieee
  • ISSN
    1536-1284
  • Type

    jour

  • DOI
    10.1109/MWC.2008.4599218
  • Filename
    4599218