HMM Sequential Hypothesis Tests for Intrusion Detection in MANETs
dc.contributor.advisor | Baras, John S. | en_US |
dc.contributor.author | Cardenas, Alvaro A. | en_US |
dc.contributor.author | Ramezani, Vahid | en_US |
dc.contributor.author | Baras, John S. | en_US |
dc.contributor.department | ISR | en_US |
dc.contributor.department | SEIL | en_US |
dc.date.accessioned | 2007-05-23T10:14:38Z | |
dc.date.available | 2007-05-23T10:14:38Z | |
dc.date.issued | 2003 | en_US |
dc.description.abstract | Most of the work for securing the routing protocols of mobile ad hoc wireless networks has been done in prevention. Intrusion detection systems play a complimentary role to that of prevention for dealing with malicious insiders, incorrect implementation and attack models. We present a statistical framework that allows the incorporation of prior information about the normal behavior of the network and of network attacks in a principled way for the detection of known and unkown attacks. For detecting an attack as soon as possible we use quickest change detection stalgorithms. We use hidden Markov models (HMMs) as a generative view of the dynamic evolution of the hop count distribution. Our results show that simple attacks can be detected by an anomaly detection framework. However, detection of more complex attacks requires incorporation of prior knowledge in the HMMs. | en_US |
dc.format.extent | 260430 bytes | |
dc.format.mimetype | application/pdf | |
dc.identifier.uri | http://hdl.handle.net/1903/6402 | |
dc.language.iso | en_US | en_US |
dc.relation.ispartofseries | ISR; TR 2003-47 | en_US |
dc.relation.ispartofseries | SEIL; TR 2003-1 | en_US |
dc.subject | Global Communication Systems | en_US |
dc.title | HMM Sequential Hypothesis Tests for Intrusion Detection in MANETs | en_US |
dc.type | Technical Report | en_US |
Files
Original bundle
1 - 1 of 1