透過您的圖書館登入
IP:18.225.149.136
  • 學位論文

行動隨意網路下抵擋路由攻擊之防禦機制

A Defense Scheme to Resist Routing Attacks in Mobile Ad Hoc Networks

指導教授 : 孫宏民

摘要


由於無線網路技術持續性地成長,行動隨意網路(MANETs)已經被廣泛地使用在軍用以及民用的應用上。基於它動態且靈活的特性,即使在沒有任何事先建立的基礎架構之下,也可以很容易的部署出一個行動隨意網路。不過,也由於它不受限制的動態拓撲性質,它很容易遭受到各種攻擊,特別是路由攻擊。例如像黑洞攻擊,它是一種可以輕易瓦解路由運作的一種攻擊。又如暴衝攻擊,即使是能力很薄弱的攻擊者也可以利用此攻擊對網路的運行造成損害。而蟲洞攻擊是一個較精密且複雜的攻擊,它也可以很容易地破壞整個網路的連結。 而這些路由攻擊也常會伴隨著封包丟棄的行為,這些攻擊者宣稱他們有路由可以幫忙傳遞資料封包,而就在資料封包經過這些攻擊者時,他們很輕易地就把這些資料封包丟棄掉。這樣的行為嚴重地影響到網路的效能,甚至可能對網路造成分割,而影響整個網路的連通性。 所以我們提出一個強韌的機制用來防禦這些路由攻擊,為了提升網路的整體效能。在此機制中,我們設計了一個比以往更好的偵測系統,可以有效地偵測出惡意節點,即使這些惡意節點互相合作,想試著去躲避偵測,我們的偵測系統也可以偵測出來。另外,為了有效地利用網路上其他節點的觀察結果,我們設計了一個安全且有效率的名譽系統,此系統可以防範惡意節點的惡意指控,並能有效地分享觀察到的資訊給網路上的其他節點。然後,我們還提出了兩種懲處方式,用來防範阻斷服務攻擊。最後,針對多種路由攻擊做了許多的模擬實驗,實驗的結果顯示我們所提出機制是可以有效地抵擋這些路由攻擊,且大幅度地提升網路整體的效能。

並列摘要


Wireless network technology is demanding and continually growing. Mobile ad hoc networks (MANETs) are extensively used in military and civilian applications. Their dynamic and flexibility allow the networks to be easily set up without the requirement of a predetermined infrastructure. However, unconstrained dynamic nature of the topology of mobile ad hoc networks makes them vulnerable to various types of attacks including routing attacks. Black hole attacks belong to one such type of attacks which disrupt the routing functions in MANETs. Rushing attacks also enable the attackers with limited resources and no cryptographic material to destroy the operation in MANETs. Wormhole attacks which are more sophisticated attacks still can easily crumble the connection in MANETs. The packet-dropping problem usually accompanies these routing attacks. The attackers claim that they have routes to forward data packets. However, when the data packets are routed through them, they drop these data packets that are supposed to be forwarded. These attacks greatly reduce the performance of the networks. Moreover, they are able to partition the network and degrade the connectivity of the network. So, we propose a robust scheme to defense these routing attacks in MANETs and improve the performance of the networks. In our scheme, we design a strong detection system to effectively detect malicious nodes in the networks. It can work properly even if multiple malicious nodes are collusive and try to circumvent the detection. For effectively utilization of the observation in the networks, we design a secure and cooperative reputation system. The proposed reputation system can prevent false accusation created by malicious nodes. Finally, we propose two mechanisms to defense various types of routing attacks. Our experiments show that the proposed mechanisms can successfully improve the throughput of the network.

並列關鍵字

無資料

延伸閱讀