Dergiler / Havacılık ve Uzay Teknolojileri Dergisi / 2013 / Cilt: 6 - Sayı: 2
Simulation and performance analysis of distributed cooperative trust based intrusion detection frameworks for MANETs
- Sayfa
- 49–57
- DOI
- —
Özet
Hareketli Geçici Ağlar (HGA) altyapısız bir topoloji oluşturan düğümler topluluğudur. Bu ağlarda, merkezi bir erişim noktası ya da merkezi bir yönetim söz konusu değildir. Bu özelliklerinden dolayı Saldırı Tespit Sistemi (STS) söz konusu olduğunda HGA’lar kendine özgü bir takım problemler ortaya koyarlar. Bu çalışmada HGA’lar için güven esasına dayalı bir saldırı tespit sistemi mimarisi ortaya konulmaktadır. Önerilen mimaride, saldırı tespit sistemi, saldırıların yerel ya da global tespitine ve düğümler arasındaki iş birliği ve güven esasına dayanmakta olup dağıtık olarak gerçekleştirilmektedir. Bu anlamda “güven” önemli bir sorun sahası oluşturmaktadır. Önerilen mimaride, düğümler, komşu düğümlerin muhtemel şüpheli davranışlarını izlemektedirler. Bir anomali söz konusu olduğunda ağ üzerinde STS uyarı mesajı yayınlanmaktadır. STS uyarı mesajlarının tekrarlanmasının izlenmesi sayesinde güven değerlendirilmesi yapılmaktadır. Önerilen mimari, iş birliği ile güven esasına dayalı, dağıtılmış bir STS ortaya koyarak, HGA’da düğümlerin devingenliğinden ve düğümlerin bencil davranma ihtimalinden kaynaklanan dezavantajları ortadan kaldırmayı hedeflemektedir.
Abstract
Mobile Ad Hoc Network (MANET) is a collection of nodes, which form an infastructureless topology. There is no central access point or centralized management. Intrusion detection in MANETs, however, is challenging for a number of reasons. This paper introduces intrusion detection architecture for MANETs, based on trust relationship and cooperation. In our proposed framework, intrusion detection system relies on local and global determination of attacks within network and intrusion detection is carried out in a distributed fashion. Reputation mechanism is used for trust assessment, which is obtained by watching the neighbor nodes behaviors. IDS alert messages are used to disseminate evidences of an intrusion attempt. A distributed IDS engine is the focal point of the architecture and we aim to utilize a cooperative trust based intrusion detection system to cope with the disadvantages drawn from mobility of nodes. In this paper, we present the feasibility of the proposed architecture by a detailed performance analyses according to the results obtained from simulations.