|
ABSTRACT
In wireless networks,the authenticity and uniqueness of node identities are essential to the fundamental operations such as routing, resource allocation, and intrusion detection. In this paper, we investigate Sybil attack, an attack in which a malicious node illegitimately acquires multiple identities and performs as these nodes simultaneously. We propose an effective approach to monitoring and detecting such attacks by integrating network security and visualization methods. The security component explores the time-varying network topology and its statistical and geometry information to detect the existence of Sybil attacks. The visualization component incorporates the detection results and provides an effective mechanism to illustrate abnormal topology patterns and locate fake identities. These two components are integrated into a practical system that takes advantage of both interactive visualization and intelligent security methods. Experimental studies are conducted to investigate the impacts of the network parameters such as node connectivity on the detection capability of the proposed mechanism.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Proceedings of IEC Workshop on Internet Simulations with the NS simulator 2000.
|
| |
2
|
|
| |
3
|
F. Anjum, D. Subhadrabandhu, and S. Sarkar. Signature based Intrusion Detection for Wireless Ad-Hoc Networks: A Comparative study of various routing protocols. In Proc. of VTC 2003.
|
 |
4
|
|
 |
5
|
|
| |
6
|
|
| |
7
|
J.-Y. Le Boudec and M. Vojnovic. Perfect Simulation and Stationarity of a Class of Mobility Models. In Proc. of IEEE Infocom 2005.
|
 |
8
|
Miguel Castro , Peter Druschel , Ayalvadi Ganesh , Antony Rowstron , Dan S. Wallach, Secure routing for structured peer-to-peer overlay networks, Proceedings of the 5th symposium on Operating systems design and implementation Due to copyright restrictions we are not able to make the PDFs for this conference available for downloading, December 09-11, 2002, Boston, Massachusetts
[doi> 10.1145/1060289.1060317]
|
| |
9
|
|
 |
10
|
|
| |
11
|
|
 |
12
|
|
 |
13
|
|
| |
14
|
W. Fan , M. Miller , S. Stolfo , W. Lee , P. Chan, Using artificial anomalies to detect unknown and known network intrusions, Knowledge and Information Systems, v.6 n.5, p.507-527, September 2004
|
| |
15
|
|
 |
16
|
Yun Fu , Jeffrey Chase , Brent Chun , Stephen Schwab , Amin Vahdat, SHARP: an architecture for secure resource peering, Proceedings of the nineteenth ACM symposium on Operating systems principles, October 19-22, 2003, Bolton Landing, NY, USA
|
| |
17
|
|
 |
18
|
|
| |
19
|
|
| |
20
|
J. Hall, M. Barbeau, and E. Kranakis. Using mobility profiles for anomaly based intrusion detection in mobile networks. In Proc. of Wireless and Mobile Security Workshop 2005.
|
 |
21
|
|
| |
22
|
|
 |
23
|
|
 |
24
|
|
 |
25
|
|
| |
26
|
Y. Livnat, J. Agutter, S. Moon, R. Erbacher, and S. Foresti. A Visualization Paradigm for Network Intrusion Detection. In Proceedings of the IEEE Information Asssurance Workshop pages 92--99, 2005.
|
| |
27
|
|
 |
28
|
Jonathan McPherson , Kwan-Liu Ma , Paul Krystosk , Tony Bartoletti , Marvin Christensen, PortVis: a tool for port-based detection of security events, Proceedings of the 2004 ACM workshop on Visualization and data mining for computer security, October 29-29, 2004, Washington DC, USA
[doi> 10.1145/1029208.1029220]
|
| |
29
|
|
 |
30
|
James Newsome , Elaine Shi , Dawn Song , Adrian Perrig, The sybil attack in sensor networks: analysis & defenses, Proceedings of the third international symposium on Information processing in sensor networks, April 26-27, 2004, Berkeley, California, USA
[doi> 10.1145/984622.984660]
|
| |
31
|
D. Rafiei and S. Curial. Effectively Visualizing Large Networks Through Sampling. In Proc. of IEEE Visualization 2005.
|
| |
32
|
|
 |
33
|
|
| |
34
|
S. Vasudevan, B. DeCleene, N. Immerman, J. Kurose, and D. Towsley. Secure Leader Election Algorithms for Wireless Ad Hoc Networks. In Proc. of IEEE DARPA Information Survivability Conference and Exposition (DISCEX)2003.
|
| |
35
|
W. Yurcik. VisFlowConnect-IP: A Link-Based Visualization of NetFlows for Security Monitoring. In 18th Annual FIRST Conference on Computer Security Incident Handling 2006.
|
 |
36
|
|
|