Report on a working session on security in wireless ad hoc networks

Report on a working session on security in wireless ad hoc networks
复制标题

DOI:
10.1145/881978.882002
复制
发表时间:
2003
期刊:
ACM SIGMOBILE Mob. Comput. Commun. Rev.
影响因子:
--
通讯作者:
L. Buttyán;J. Hubaux
L. Buttyán;J. Hubaux
中科院分区:
其他
文献类型:
--
作者:
L. Buttyán;J. Hubaux

文献摘要

被引文献

相似文献

移动的Ad Hoc网络(MANET)技术的出现提倡通信设备的自组织无线互连,其将扩展有线网络基础设施或与有线网络基础设施协同操作,或者可能地演进为自治网络。在任何一种情况下,基于MANET的应用程序的扩散取决于多种因素,可信度是要满足的主要挑战之一。尽管存在众所周知的安全机制,但与这种新的网络模式相关的其他漏洞和功能可能会使这种传统解决方案不适用。特别是,在开放和分布式通信环境中缺乏中央授权设施是一个重大挑战,特别是由于需要合作网络操作。特别地,在MANET中,任何节点都可能通过中断路由发现过程而损害路由协议功能。在本文中,我们提出了一个路由发现协议,减轻这种恶意行为的不利影响,以提供正确的连接信息。我们的协议保证,伪造的,妥协的,或重放的路由答复将被拒绝或永远不会回到查询节点。此外,协议响应性在利用路由协议本身的不同类型的攻击下得到保障。所提出的方案的唯一要求是发起查询的节点和所寻求的目的地之间存在安全关联。具体地,没有对中间节点做出假设,中间节点可能表现出任意和恶意的行为。该方案在存在多个非合谋节点的情况下具有鲁棒性,并能及时提供准确的路由信息。
The emergence of the Mobile Ad Hoc Networking (MANET) technology advocates self-organized wireless interconnection of communication devices that would either extend or operate in concert with the wired networking infrastructure or, possibly, evolve to autonomous networks. In either case, the proliferation of MANET-based applications depends on a multitude of factors, with trustworthiness being one of the primary challenges to be met. Despite the existence of well-known security mechanisms, additional vulnerabilities and features pertinent to this new networking paradigm might render such traditional solutions inapplicable. In particular, the absence of a central authorization facility in an open and distributed communication environment is a major challenge, especially due to the need for cooperative network operation. In particular, in MANET, any node may compromise the routing protocol functionality by disrupting the route discovery process. In this paper, we present a route discovery protocol that mitigates the detrimental effects of such malicious behavior, as to provide correct connectivity information. Our protocol guarantees that fabricated, compromised, or replayed route replies would either be rejected or never reach back the querying node. Furthermore, the protocol responsiveness is safeguarded under different types of attacks that exploit the routing protocol itself. The sole requirement of the proposed scheme is the existence of a security association between the node initiating the query and the sought destination. Specifically, no assumption is made regarding the intermediate nodes, which may exhibit arbitrary and malicious behavior. The scheme is robust in the presence of a number of non-colluding nodes, and provides accurate routing information in a timely manner.