An effective intrusion detection approach for OLSR MANET protocol

An effective intrusion detection approach for OLSR MANET protocol
复制标题

一种有效的OLSR MANET协议入侵检测方法

DOI:
10.1109/npsec.2005.1532054
复制
发表时间:
2005
期刊:
1st IEEE ICNP Workshop on Secure Network Protocols, 2005. (NPSec).
影响因子:
--
通讯作者:
M. Gorlatova
M. Gorlatova
中科院分区:
--
文献类型:
--
作者:
M. Wang;L. Lamont;P. Mason;M. Gorlatova

文献摘要

参考文献

被引文献

相似文献

优化链路状态路由(OLSR)协议是一种主动移动自组网(MANET)路由协议。OLSR协议中没有设计安全方面,因此容易受到各种攻击。最近的研究工作集中在提供身份验证和加密技术,以保护OLSR协议免受外部入侵者的攻击。需要第二道防线来提供入侵检测和响应技术,以保护OLSR协议免受内部入侵者的攻击。本文描述了OLSR MANET路由协议面临的安全威胁,提出了一种基于协议语义检测的入侵检测方案。我们的方法基于协议定义中隐含的语义属性,并指定正确的OLSR路由更新行为。每个MANET节点都采用了基于语义属性的冲突检测。任何异常的协议语义都会触发入侵警报。虽然我们以OLSR为例,但我们认为所提出的方法可以应用于任何多点中继(MPR)主动MANET协议。
The optimized link state routing (OLSR) protocol is a proactive mobile ad hoc network (MANET) routing protocol. Security aspects have not been designed into the OLSR protocol and therefore make it vulnerable to various kinds of attacks. Recent research efforts have focused on providing authentication and encryption techniques to secure the OLSR protocol against attacks from outside intruders. A second line of defense is required to provide intrusion detection and response techniques in protecting the OLSR protocol against attacks from inside intruders. In this paper, we describe security threats to the OLSR MANET routing protocol and present an intrusion detection solution based on protocol semantics checking. Our approach is based on semantic properties that are implied in the protocol definition and specify the correct OLSR routing update behavior. Conflict checking based on semantic properties is applied in every MANET node. Any abnormal protocol semantics triggers an intrusion alarm. While we use OLSR as an example, we argue that the presented approach can be applied to any multi-point relay (MPR) proactive MANET protocol.
DOI: 10.1145/359168.359176
发表时间: 1979-01-01
影响因子: 22.7
作者:
SHAMIR, A
通讯作者: SHAMIR, A