位置:成果数据库 > 期刊 > 期刊详情页
基于模糊行为分析的移动自组网入侵检测
  • ISSN号:1000-1239
  • 期刊名称:《计算机研究与发展》
  • 时间:0
  • 分类:TP393.08[自动化与计算机技术—计算机应用技术;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]中国科学院软件研究所信息安全国家重点实验室,北京100080
  • 相关基金:国家自然科学基金项目(60273027);国家“八六三”高技术研究发展计划基金项目(2003AA142150)With rapid development of wireless communications, mobile ad hoc networks are being deployed into more and more areas. The current hot research points for ad hoc networks are focused on routing and security. Protection schemes and intrusion detection schemes are both extensively studied nowadays. Though some intrusion detection schemes have been proposed, they are still unsatisfactory. This work presents a new intrusion detection scheme for ad hoc networks. The scheme makes use of the idea of specification based detection, and introduces the fuzzy method into our detection mechanism. By considering the network status in detection, our scheme can detect intrusions more effectively and more accurately. This work is supported by the National High-Tech Research and Development Plan of China under grant No. 2003AA142150, and by the National Natural Science Foundation of China No. 60273027.
中文摘要:

移动自组网络是一种不需要基础设施的网络.在这种网络中,移动节点是自组织的,并且需要互相提供网络路由服务.自组网络非常容易受到攻击,特别是内部攻击.提出了一个基于模糊行为分析的入侵检测方案,以检测网络内部的路由攻击.利用邻接节点监测,通过分析节点路由行为与路由规范的偏差,发现恶意行为.在数据分析的过程中引入了模糊路由行为分析的方法,大大降低了误报率.仿真实验表明,该方案能有效地检测出路由入侵行为,而将误报率控制在一个较低的水平.

英文摘要:

Mobile ad hoc network is a kind of network that does not need infrastructure. In such networks mobile nodes are self-organized and provide network routing for each other. Ad hoc networks are extremely vulnerable to attacks, especially internal attacks. In this paper, an intrusion detection scheme is proposed to detect internal routing attacks. In the scheme, every node monitors its adiacent nodes and tries to detect their misbehavior by analyzing the difference between their route behavior and the route specification. An FBA (fuzzy behavior analysis)method is introduced into the data analysis procedure, which can greatly decrease the false alarm rate. Simulation result shows that the scheme can effectively detect intrusions, while keeping the false alarm rate comparatively low.

同期刊论文项目
同项目期刊论文
期刊信息
  • 《计算机研究与发展》
  • 中国科技核心期刊
  • 主管单位:中国科学院
  • 主办单位:中国科学院计算技术研究所
  • 主编:徐志伟
  • 地址:北京市科学院南路6号中科院计算所
  • 邮编:100190
  • 邮箱:crad@ict.ac.cn
  • 电话:010-62620696 62600350
  • 国际标准刊号:ISSN:1000-1239
  • 国内统一刊号:ISSN:11-1777/TP
  • 邮发代号:2-654
  • 获奖情况:
  • 2001-2007百种中国杰出学术期刊,2008中国精品科...,中国期刊方阵“双效”期刊
  • 国内外数据库收录:
  • 俄罗斯文摘杂志,荷兰文摘与引文数据库,美国工程索引,日本日本科学技术振兴机构数据库,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版),中国北大核心期刊(2000版)
  • 被引量:40349