Title :
Control theoretic approach to intrusion detection using a distributed hidden Markov model
Author :
Khanna, Rahul ; Liu, Huaping
Author_Institution :
INTEL Corp., Santa Clara, CA
Abstract :
Cooperative ad hoc wireless networks are more vulnerable to malicious attacks than traditional wired networks. Many of these attacks are silent in nature and cannot be detected by conventional intrusion detection methods such as traffic monitoring, port scanning, or protocol violations. These sophisticated attacks operate under the threshold boundaries during an intrusion attempt and can only be identified by profiling the complete system activity in relation to normal behavior. In this article we discuss a control-theoretic hidden Markov model strategy for intrusion detection using distributed observation across multiple nodes. This model comprises a distributed HMM engine that executes in a randomly selected monitor node and functions as a part of the feedback control engine. This drives the defensive response based on hysteresis to reduce the frequency of false positives, thereby avoiding inappropriate ad hoc responses.
Keywords :
ad hoc networks; hidden Markov models; mobile radio; telecommunication control; telecommunication security; three-term control; cooperative ad hoc wireless network; distributed hidden Markov model; feedback control engine; intrusion detection; Communication system traffic control; Engines; Feedback control; Hidden Markov models; Hysteresis; Intrusion detection; Monitoring; Protocols; Traffic control; Wireless networks;
Journal_Title :
Wireless Communications, IEEE
DOI :
10.1109/MWC.2008.4599218