4.5 Article

RAPID: Traffic-agnostic intrusion detection for resource-constrained wireless mesh networks

Journal

COMPUTERS & SECURITY
Volume 46, Issue -, Pages 1-17

Publisher

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2014.07.002

Keywords

Resource-constrained wireless mesh networks; Intrusion detection; Traffic-agnostic; Link-coverage monitoring; Genetic algorithm; Multi-interface Snort

Funding

  1. NABSSUP Fleet Logistics Center San Diego [N00244-12-1-0036]
  2. NSF [1127449, 1145858, 0923203]

Ask authors/readers for more resources

Due to the recent increased interest in wireless mesh networks (WMN), their security challenges have become of paramount importance. An important security mechanism for WMN, intrusion detection, has received considerable attention from the research community. Recent results show that traditional monitoring mechanisms are not applicable to real-world WMN due to their constrained resources (memory and processing power), which result in high false negative rates since only a few IDS functions can be activated on monitoring nodes. Cooperative solutions, on the other hand, have high communication overhead and detection delay when the traffic load is high. A practical traffic-aware IDS solution was recently proposed for resource-constrained WMN, however, traffic-awareness might not be feasible for some WMN applications. This article proposes a traffic-agnostic IDS solution that uses a link-coverage approach to monitor both local and backbone WMN traffic. Using real-world experiments and extensive simulations, we show that our proposed IDS solutions outperform traffic-aware IDS solutions while incurring lower computation and communication overhead. (C) 2014 Elsevier Ltd. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.5
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available