A Novel Architecture of Intrusion Detection System

In this paper, we propose a novel Intrusion Detection System (IDS), Court-like Cluster-based IDS (CCIDS), to secure routing protocoh: in Mobile Ad Hoc Networks (MANETs). After the network is divided into one-hop clusters, each of these clusters performs similar functions as a court in real-life, such as accusation, investigation and defence. We show that court like IDS is effective in many aspects, especially the capability to prevent malicious alerts and reduce false positive rate. To further prove its effectiveness, we then apply CCIDS in securing the Optimized Link State Routing (OLSR) protocol to solve two most severe attacks--link spoofing and link deletion. Through extensive simulation, four performance parameters, namely, detection rate, false positive rate, detection delay, and communication overhead are evaluated.

[1]  Karl N. Levitt,et al.  A Specification-Based Intrusion Detection Model for OLSR , 2005, RAID.

[2]  Abbas Jamalipour,et al.  SA-OLSR: Security Aware Optimized Link State Routing for Mobile Ad Hoc Networks , 2008, 2008 IEEE International Conference on Communications.

[3]  Wenke Lee,et al.  A cooperative intrusion detection system for ad hoc networks , 2003, SASN '03.

[4]  Farouk Kamoun,et al.  CASAN: Clustering algorithm for security in ad hoc networks , 2008, Comput. Commun..

[5]  M. Wang,et al.  An effective intrusion detection approach for OLSR MANET protocol , 2005, 1st IEEE ICNP Workshop on Secure Network Protocols, 2005. (NPSec)..