DocumentCode
835456
Title
Control theoretic approach to intrusion detection using a distributed hidden Markov model
Author
Khanna, Rahul ; Liu, Huaping
Author_Institution
INTEL Corp., Santa Clara, CA
Volume
15
Issue
4
fYear
2008
Firstpage
24
Lastpage
33
Abstract
Cooperative ad hoc wireless networks are more vulnerable to malicious attacks than traditional wired networks. Many of these attacks are silent in nature and cannot be detected by conventional intrusion detection methods such as traffic monitoring, port scanning, or protocol violations. These sophisticated attacks operate under the threshold boundaries during an intrusion attempt and can only be identified by profiling the complete system activity in relation to normal behavior. In this article we discuss a control-theoretic hidden Markov model strategy for intrusion detection using distributed observation across multiple nodes. This model comprises a distributed HMM engine that executes in a randomly selected monitor node and functions as a part of the feedback control engine. This drives the defensive response based on hysteresis to reduce the frequency of false positives, thereby avoiding inappropriate ad hoc responses.
Keywords
ad hoc networks; hidden Markov models; mobile radio; telecommunication control; telecommunication security; three-term control; cooperative ad hoc wireless network; distributed hidden Markov model; feedback control engine; intrusion detection; Communication system traffic control; Engines; Feedback control; Hidden Markov models; Hysteresis; Intrusion detection; Monitoring; Protocols; Traffic control; Wireless networks;
fLanguage
English
Journal_Title
Wireless Communications, IEEE
Publisher
ieee
ISSN
1536-1284
Type
jour
DOI
10.1109/MWC.2008.4599218
Filename
4599218
Link To Document