河图雷达武汉东湖表面波浪探测实验_第1页
河图雷达武汉东湖表面波浪探测实验_第2页
河图雷达武汉东湖表面波浪探测实验_第3页
河图雷达武汉东湖表面波浪探测实验_第4页
河图雷达武汉东湖表面波浪探测实验_第5页
全文预览已结束

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

中国中国--PAGE1SinkholeAttackDetectioninClustered-basedSelf-organizingNetworksZhangFangjiao1,2,ZHAI (1.SchoolofComputing,BeijingUniversityofPostsandTelecommunications;2.InstituteofInformationEngineering,ChineseAcademyofScience)Abstract:Self-organizingnetworkshasvastappliedforegroundinthefuturebecauseofitslow-cost,save-power,andeasyimplementationetc.Butinsuchmanyapplications,someofthemplacehighdemandsonit.Andsafetybecomescriticalforwideapplication.Sinkholeattackisacommonattack,10whicheasilyiscombinedwithotherattackstocausemoredamage.Inthispaper,amethodtodetectthesinkholeattackisproposed.Twoargumentsareraisedtohelpdetectthenodessufferingfromsinkholeattack,CreditRatingandFlowdifference.Keywords:sinkholeattack;detection;self-organizingnetworks; 15Aself-organizingnetworkisamulti-hoptemporaryautonomoussystemmadeupofagroupofmobilenodeswithwirelesstransmittersandreceivers.Notrelyingonanypresetinfrastructure,itwouldachieveautomaticorganizationandrunningofthenetworkinarbitrarymeshtopology.Togetherwithmicro-processingandwirelesscommunicationcapabilities,itiswidelyusedonoccasionswhichrequirerapiddeploymentanddynamicnetworking,suchasmilitary20communicationsandemergencycommunications.Theself-organizingnetworkisbecomingaresearchsubjectofgreatsignificanceinpracticalapplication.Withrapiddevelopmentofwirelesscommunicationandelectronicdevicestechnology,thestatehasalsofurtherincreaseditsinputinresearchanddevelopmentoflowcostlowenergyconsumptionwirelesssensor.However,thereareavarietyofattacksthatthreatennetworksecurityinself-25networks,includingSybilattacks,selectiveforwardingattack,SinkholeattackWormholeattacksandHELLOFLOODattacks.Eachnodeinnetworksisnotonlydataterminal,butalsoarouterresponsibleforforwardingdatapackets,whichmakestheroutingprotocolconsiderableinthewholenetwork.Manyoftheattacksjusttakeadvantageoftheprotocolloopholelaunchingmaliciousattackbythecapturednodewithinthenetwork,stealingprivacyinformation,30badlyaffectthenormaloperationofnetworksandendangerthesafetyofthenetwork.Atitsworst,thenetworkswouldbeparalyzed,leadingtoagreatloss.Sinkholeattack,mainlydiscussedinthispaper,isarelativelycommonattack.Thenodesattackedclaimtobeabletoprovideasingle-hop,high-qualitypathtothebasestation,whichattractstheneighbornodestochangetheoriginalroute.Andpacketssenttothebasestation35discardedorforwardedtothesinkholeattacker,whichseriouslydamagestheloadbalancingofthenetworkandalsoprovidesaplatformforotherattacks.Itiseasilycombinedwithotherattacks,causinggreaterdamagetothenetwork.Thecurrentresearchinthisareaisrare,especiallyinourcountry.Hereisanewapproachtotestifnodesaresufferingfromsinkholeattackbasedonpriorworks.Theprocessismainlycompletedbythetwo40attributesofnodes,CreditratingandTrafficdifference.Boththesinglenodeattackedandmanycollaboratingnodescouldbedetectedeffectivelywhichisthemaincontributionofthepaper.Briefauthorintroduction:ZhangFangjiao(1989-),female,astudentfromBeijingUniversityofPostsandTelecommunications,researchinsecurityofInternetofThingsandmobileInternetandsoonTherestofthepaperisorganizedasfollows.InSectionII,someresearchworkbeforeaboutsinkholeattackisintroducedbriefly.InSectionIII,thenewapproachweraiseisdiscussedthoroughly,akeypointinthepaper.SectionIVtellssimulationandanalysisoftheidea.Finally,45wesummarizeourworkinafew1RelatedSofar,someresearchershaveputforwardvarioussolutionstosinkholeattackathomeandabroad,aconsiderablepartofwhicharesafepoliciesbasedonencryptionalgorithm,suchasSARin[1]andSEAD[2].Thesesecureroutingprotocolscouldprovidebetterguaranteeforsecure50routing.Butthesestrategiesneedtoaddcomplexencryptionalgorithm,decryptionalgorithmandrespondingprotocol,whicharemuchmorecomplicatedandpayahighpriceforsecurity.Ofcourse,therearealsosomeothermethodsrelativelysimplethatcouldsolvethesinkholeattack.M.Al-shurmanetalin[3]mentionthatredundantroutingsareusedtotestnodes.Atleastthreedifferentroutingaredetectedandthesourcenodepingsthem.Thesourcenodechecksreplies55frommaliciousnodesandthedestinationtojudgethenodesafeornot.Onlywhenthesaferoutingisrecognized,doesthenodesendstoreddata.S.Martietalproposetwoconcepts-WatchdogandPathraterin[4].ItisassumedthatnodeAcouldmonitorthecontentsofnodeC,whileCcanalsomonitorA.WhensendingpacketstonexthopnodeC,nodeA,knowingDisthenexthopofC,canlistenpacketsCforwardingtoD.So,everynodeistheWatchdogofothernodes.Ifnot60forwardingthepacketfromitpriornode,thenextnodeisjudgedabnormalanditmaybeI.Adaetalin[5]usethecreditratingtocheckthecredibilityofnodesinthenetwork.Thismethodreliesontheexactpathofpacketsgothrough.Ifpacketsaresuccessfullytransferredthroughapath,thenthecreditratingofnodesonthepathwouldbeincreased.Onthecontrary,decreasethecreditratingofnodes.Othernodesremainasbefore.Ourworkisjustspiredbytheidea.Inthe65recognitionandunderstandingofsinkholeattack,manyinnovativesolutionsalsoemerge,whichhavehugeimprovementinperformance.[6,7]refertoanapproachbyvalidatingtheresponseinformationfromthenexthopneighbornode.WhennodeCinformsnodeAthatnodeBisthenexthop,nodeAdoesnotimmediatelybelieveitandwouldsendenquirypackettoNodeBtocheckifthereisaroutefromBtodestination. Themethodsmentionedabovecouldavoidthesinkholeattacktosomedegree,buttheyaimedatsinglemaliciousnode,notconsideringthecasethatsomemaliciousnodesactcooperativelywitheachother.Then,theresultsobtainedarefalse.However,afewstudieshavebeendoneformutualcooperation.In[8],theapproachbyvalidatingtheresponseinformationfromthenexthopneighbornodeisimprovedtobesuitabletomanymaliciousnodes.Thesourcenodeexaminesneighbor75nodetovalidatetodeterminetheauthenticityofinformationreceivedandadoptrecursivemulti-hopauthenticationtopreventanaccompliceattack.Inordernottofallintoinfiniteloopverification,anadjustableparametervariableisintroduced.However,itisdifficulttoknowwhattheparameterisonearth.Ourworkcouldalsoplayacertainroleinavoidingmostofmanymaliciousnodesattack.802SinkholeattackTocompletethesinkholeattackdetectionprocess,twoparametersareraised,creditratingandflowdifference.Thedetailedexplanationisgivenbelow.Creditratingrepresentscredibilityofthesensornode,thatishowmuchIcouldtrustthenode. canbecalculatedaccordingtothealgorithm.Supposethecreditratingofthesensornodei

{1,2,3,……,m})inanyclusterisCi.Anditsinitialvalueequalszero.Whenapacketisforwardedsuccessfullythroughalink,thenallthenode’screditratingvalueincreasesonthelink.Instead,thenode’scredibilitydecreases.Thesensornodesleftremainthevalue.Therewouldbehighestandlowestcreditratingineachclusterarea,whichcanbecalculatedbytheclusterheadutilizingstatisticmethods.WenamethemChandClrespectively.Flowdifferenceisdefinedasthetrafficgapbetweenleavingthenodeandenteringthenode.Normally,thevalueshouldbenon-negativebecausethenodehastotransferthedatagatheredbyitselfinadditiontoforwardothernodes’packets.SinkholeAttackScenario:weproposedonemethodusedtodetectthenodesthatareundersinkholeattack.ThetopologyisdepictedasFig.1.Inthefigure,S1representscollectioncomposedofsuspiciousnodesandthecollectionS2containsnodesattackedbysinkhole.Therearenclusterareasinthemonitoringarea,aninteger.Everyclusterareacontainsmcommonnodes,anintegertoo.Themonitoringdevicemonitorsthetrafficofeachclusterhead.Andclusterheadskeeptrackofthecommonnodes’creditratingandflowdifferenceincorrespondingclusterareaperiodically.

Fig.1Self-organizingNetworkTheprocesstodetectthenodessufferfromsinkholeattackisshowninFig.2.Itcanberoughlydividedintothreesteps.Step1:tomonitorclusterheads’Themonitordevicetracksanddisplaysflowchangeofalltheclusterheadsintheself-organizingnetworkonareal-timebasis.Asisknowntoall,theflowofclusternodesshouldbeverysmoothforaperiod.AndwesetittoT.Itisimpossibleformajorchange.IfthenumberofpacketstransferringfromoneclusterheadtothebasestationdropssharplyandsuchphenomenonlastsforT1ormuchlonger,therespondingclusterareaisjudgedtobeabnormal.T1isin1-minuteunitandrangesfrom1to10.Next,theclusterareawouldbeanalyzedandtestedparticularly.Step2:toformsuspiciousnodessetThereexistssuchacasethatmanymaliciousnodescollaboratewitheachothertoincreasetheircreditratingssothattheircreditratingsareextravagantlyhigh.Thus,wethinknodesarenotcredibleuntiltheircreditratingsarebetweenClandCh.Supposeclusterarea1isabnormal.

Troughcontinuouscycledetectiontonodesinclusterarea1,placethenodeswhosecreditratingsarelessthanClormorethanChintothesuspiciousnodessetS1.Then,nodesinS1wouldbeanalyzedfurtherbytheflowdifference.Similarly,checkthenodesinS1cyclicallytoseewethertheirflowdifferenceisnegativeornot.Iftheywere,theywouldbecategorizedtodevelopnewsetS2,containingthenodesreallysufferingfromsinkholeattack.Inthisstep,nodeswithhighercreditratingareexcludedbecauseofbigdataflowitself.Step3:toformsinkholeattacknodessetAfterstep2,thenodesfinallyarefixedthataresufferingsinkhole.Anwarningisproducedinthemonitoringdeviceinordertodefendagainstanddealwithsinkholeattack.Byconductingtheabovethreesteps,nodeshavebeenattackedaredetectedeffectivelyandalsoanalarmwarningsendstothemonitordeviceandgainpeople’sattention.Itcouldbeagainstagreatloss.Themostmeaningfulisthattheapproachnotonlycansolvethesinglemaliciousnodeattackinself-organizingnetworks,butalsocandetectseveralcollaboratingmaliciousnodes,whichisthemostimportantthinginthearticle.Fig.2SinkholeAttackNodesDetection

Inthepaper,basedontheattributesofsinkholeattack,twoparametersareproposedtopreventit,CreditratingandFlowdifference.Thesimulationalsoprovesthefeasibilityoftheapproachforbothsinglemaliciousnodeandcoordinatedattackofmanynodes,whichisthemaincontributionofthepaper.Infuture,wewouldperfectthemethodabove,especiallyinsimulationandYCHu,DBJohnson,APerrig.SEAD:secureefficientdistancevectorroutingformobilewirelessadhocnetworks[J].The

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论