New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system

Mobile Adhoc Network (MANET) is vulnerable to network attacks due toits open communication medium. Blackhole and wormhole attacks are the mostsevere attacks in the network. The attacks cause congestion and increase thepossibility of confidential data theft. Unfortunately, the existing security solut...

Full description

Saved in:
Bibliographic Details
Main Author: Mandala, Satria
Format: Thesis
Language:English
Published: 2012
Subjects:
Online Access:http://eprints.utm.my/id/eprint/32318/1/SatriaMandalaPFSKSM2012.pdf
http://eprints.utm.my/id/eprint/32318/
http://dms.library.utm.my:8080/vital/access/manager/Repository?query=New+framework+for+securing+mobile+adhoc+network+using+lightweight+authentication+and+signature-based+intrusion+detection+system&queryType=vitalDismax&public=true
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknologi Malaysia
Language: English
id my.utm.32318
record_format eprints
spelling my.utm.323182020-11-12T08:26:05Z http://eprints.utm.my/id/eprint/32318/ New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system Mandala, Satria T Technology (General) Mobile Adhoc Network (MANET) is vulnerable to network attacks due toits open communication medium. Blackhole and wormhole attacks are the mostsevere attacks in the network. The attacks cause congestion and increase thepossibility of confidential data theft. Unfortunately, the existing security solutionsare insufficient to protect the network. This work proposed a new securityframework, named Extra Secure Adhoc on Demand Distance Vector (ESAODV).This framework provides a defense-in-depth protection through layered securitymeasures: secure protocol and intrusion detection system (IDS) with extracountermeasures. The first layer implements lightweight packet authentication,and the second layer monitors and counters malicious packets. In this study,ESAODV was implemented using Java in Time Simulator/Scalable WirelessAdhoc Network Simulator, and analyzed using R-Statistics, Sigma Plot andMinitab. Results showed that ESAODV had contained the blackhole attackand the hybrid blackhole attack (HBHA) effectively. The number of corruptingrouting tables of benign nodes could be minimized to be near zero even if thenumber of attackers were increased. In addition, the IDS accurately detectedthe wormhole and the variant of wormhole attack called diversion of packet overthe wormhole link (DP-WHL). The false positive for live attack detection wassmall. The accuracy of detection was more than 94.5 percent. Although attackerschanged the pattern of packets diversion, the IDS detected the new attack patternin near real time. In addition to these findings, this research has also modeledfour performance metrics data of ESAODV, i.e., memory usage, elapsed timefor completing routing tasks, number of route replies and route success, basedon both linear regression and neural network. Goodness of fit parameters forthe models based on the neural network was higher than the linear regression. ESAODV has been proven to provide a comprehensive protection from the mostsevere attacks in the network. Furthermore, the performance metrics of ESAODVbased on the neural network produced a superior model. 2012 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/id/eprint/32318/1/SatriaMandalaPFSKSM2012.pdf Mandala, Satria (2012) New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system. PhD thesis, Universiti Teknologi Malaysia, Faculty of Computer Science and Information System. http://dms.library.utm.my:8080/vital/access/manager/Repository?query=New+framework+for+securing+mobile+adhoc+network+using+lightweight+authentication+and+signature-based+intrusion+detection+system&queryType=vitalDismax&public=true
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic T Technology (General)
spellingShingle T Technology (General)
Mandala, Satria
New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
description Mobile Adhoc Network (MANET) is vulnerable to network attacks due toits open communication medium. Blackhole and wormhole attacks are the mostsevere attacks in the network. The attacks cause congestion and increase thepossibility of confidential data theft. Unfortunately, the existing security solutionsare insufficient to protect the network. This work proposed a new securityframework, named Extra Secure Adhoc on Demand Distance Vector (ESAODV).This framework provides a defense-in-depth protection through layered securitymeasures: secure protocol and intrusion detection system (IDS) with extracountermeasures. The first layer implements lightweight packet authentication,and the second layer monitors and counters malicious packets. In this study,ESAODV was implemented using Java in Time Simulator/Scalable WirelessAdhoc Network Simulator, and analyzed using R-Statistics, Sigma Plot andMinitab. Results showed that ESAODV had contained the blackhole attackand the hybrid blackhole attack (HBHA) effectively. The number of corruptingrouting tables of benign nodes could be minimized to be near zero even if thenumber of attackers were increased. In addition, the IDS accurately detectedthe wormhole and the variant of wormhole attack called diversion of packet overthe wormhole link (DP-WHL). The false positive for live attack detection wassmall. The accuracy of detection was more than 94.5 percent. Although attackerschanged the pattern of packets diversion, the IDS detected the new attack patternin near real time. In addition to these findings, this research has also modeledfour performance metrics data of ESAODV, i.e., memory usage, elapsed timefor completing routing tasks, number of route replies and route success, basedon both linear regression and neural network. Goodness of fit parameters forthe models based on the neural network was higher than the linear regression. ESAODV has been proven to provide a comprehensive protection from the mostsevere attacks in the network. Furthermore, the performance metrics of ESAODVbased on the neural network produced a superior model.
format Thesis
author Mandala, Satria
author_facet Mandala, Satria
author_sort Mandala, Satria
title New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
title_short New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
title_full New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
title_fullStr New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
title_full_unstemmed New framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
title_sort new framework for securing mobile adhoc network using lightweight authentication and signature-based intrusion detection system
publishDate 2012
url http://eprints.utm.my/id/eprint/32318/1/SatriaMandalaPFSKSM2012.pdf
http://eprints.utm.my/id/eprint/32318/
http://dms.library.utm.my:8080/vital/access/manager/Repository?query=New+framework+for+securing+mobile+adhoc+network+using+lightweight+authentication+and+signature-based+intrusion+detection+system&queryType=vitalDismax&public=true
_version_ 1684653427044384768