计算机与现代化

• 信息安全 • 上一篇    下一篇

基于链接全覆盖的无线Mesh网络入侵检测算法

  

  1. (沈阳军区总医院信息科,辽宁沈阳110015)
  • 收稿日期:2016-06-20 出版日期:2017-03-09 发布日期:2017-03-20
  • 作者简介:褚贵洋(1982-),男,吉林白城人,沈阳军区总医院信息科工程师,研究方向:计算机网络。

Wireless Mesh Network Intrusion Detection Algorithm Based on Link Complete Coverage

  1. (Information Department, General Hospital of Shenyang Military Area Command, Shenyang 110015, China)
  • Received:2016-06-20 Online:2017-03-09 Published:2017-03-20

摘要:

已有的Wireless Mesh Network安全监控方案并未考虑WMN中节点的内存资源限制,其实用性较差。本文从2个角度出发,基于链接全覆盖提出中心型与分布式2种入侵检测算法。中心型检测方案基于基站统一检查各链接的安全性,采用遗传算法寻找链接全覆盖问题的最优解,从而提高入侵检测的准确率;分布式检测方案基于内存资源开销的预算机制自适应地将IDS(入侵检测系统)分布于剩余内存资源较多的节点,较好地平衡了各节点的内存资源开销。仿真实验结果表明,本文2种方法对于单跳、多跳入侵攻击与妥协攻击均具有较高的安全性。

关键词: 无线Mesh网络, 安全性, 入侵检测, 妥协攻击, 资源成本

Abstract:

 The existing wireless mesh network (WMN) security monitoring methods do not consider the resource constraint of the nodes in WMN, so they are not practical. Centralized and distributed intrusion detection algorithms are proposed based on the link complete coverage. The security of each link is maintained by base station in centralized intrusion detection algorithm, and the genetic algorithm is used to find the optimized solution of the problem of link complete coverage, so the detection rate is improved; IDS is adaptively distributed into the nodes with enough remaining resource based on the prediction machinery of the resource cost, so the resource cost of each node is balanced. Simulation experiments results show that the proposed two methods are of better security in single hop intrusion attack, multi-hop intrusion attack, and compromised attack.

Key words:  wireless mesh network, security, intrusion detection, compromised attack, resource cost

中图分类号: