Real-time detection of traffic anomalies in wireless mesh networks

被引:6
|
作者
Zaidi, Zainab R. [1 ,5 ]
Hakami, Sara [2 ,4 ]
Landfeldt, Bjorn [3 ,4 ]
Moors, Tim [2 ]
机构
[1] Networked Syst Grp, NICTA, Alexandria, NSW 1435, Australia
[2] UNSW, Sch EE&T, Sydney, NSW 2052, Australia
[3] USyd, Sch IT, Sydney, NSW 2006, Australia
[4] NICTA, Alexandria, NSW, Australia
[5] George Mason Univ, Network Architecture Lab, Fairfax, VA 22030 USA
关键词
Anomaly detection; Wireless mesh networks; Principal component analysis; Chi-square statistics; Denial-of-service; Port scan;
D O I
10.1007/s11276-009-0221-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection is emerging as a necessary component as wireless networks gain popularity. Anomaly detection has been addressed broadly in wired networks and powerful methods have been developed for correct detection of a variety of known attacks and other anomalies. In this paper, we propose a real-time anomaly detection and identification scheme for wireless mesh networks (WMN) using components from previous methods developed for wired networks. Experiments over a WMN testbed show the effectiveness of the proposed scheme in isolating different types of anomalies, such as Denial-of-service attacks, port scan attacks, etc. Our scheme uses Chi-square statistics and it is based on similar ideas as the scheme presented by Lakhina et al. although it has lower computational complexity. The original method by Lakhina et al. was developed for wired networks and used Principal Component Analysis (PCA) for reducing the dimensions of observed data and Hotelling's t (2) statistics to distinguish between normal and abnormal traffic conditions. However, in our studies we found that dimension reduction is the most computationally intensive process of the scheme. In this paper we propose an alternative way of reducing dimensions using flow variances in a Chi-square test. Experimental results show that the Chi-square test performs similarly well to the PCA-based method at merely a fraction of the computations. Moreover, we propose an automatic identification scheme to pin-point the cause of the detected anomaly and its contribution in terms of additional or lack of traffic. Our results and comparison with other statistical tools show that the Chi-square test and the PCA-based method with identification scheme make powerful tools for real-time detection of various anomalies in an interference prone wireless networking environment.
引用
收藏
页码:1675 / 1689
页数:15
相关论文
共 50 条
  • [21] Resource allocation for real-time and non-real-time traffic in wireless networks
    Tzeng, Show-Shiow
    [J]. COMPUTER COMMUNICATIONS, 2006, 29 (10) : 1722 - 1729
  • [22] Real-Time Jamming Detection in Wireless IoT Networks
    Zahra, Fatima Tu
    Bostanci, Yavuz Selim
    Soyturk, Mujdat
    [J]. IEEE ACCESS, 2023, 11 : 70425 - 70442
  • [23] Prototypes of opportunistic wireless mesh networks supporting real-time services
    Song, Liang
    Hatzinakos, Dimitrios
    [J]. 2008 5TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-3, 2008, : 386 - 387
  • [24] Real-time QoE Prediction for Multimedia Applications in Wireless Mesh Networks
    Aguiar, Elisangela
    Riker, Andre
    Cerqueira, Eduardo
    Abelem, Antonio
    Mu, Mu
    Zeadally, Sherali
    [J]. 2012 IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE (CCNC), 2012, : 592 - 596
  • [25] A real-time node-based traffic anomaly detection algorithm for wireless sensor networks
    Onat, I
    Miri, A
    [J]. 2005 SYSTEMS COMMUNICATIONS, PROCEEDINGS: ICW 2005, WIRELESS TECHNOLOGIES; ICHSN 2005, HIGH SPEED NETWORKS; ICMCS 2005, MULTIMEDIA COMMUNICATIONS SYSTEMS; SENET 2005, SENSOR NETWORKS, 2005, : 422 - 427
  • [26] Delay Analysis of Wireless Broadband Networks with Non Real-Time Traffic
    Andreev, Sergey
    Saffer, Zsolt
    Turlikov, Andrey
    [J]. MULTIPLE ACCESS COMMUNICATIONS, 2011, 6886 : 206 - +
  • [27] Resource allocation for real-time traffic in unreliable wireless cellular networks
    Jun Xu
    Chengcheng Guo
    Hao Zhang
    Jianfeng Yang
    [J]. Wireless Networks, 2018, 24 : 1405 - 1418
  • [28] QoS support of real-time multimedia traffic in wireless IP networks
    Lee, KS
    El Zarki, M
    [J]. MULTIMEDIA SYSTEMS AND APPLICATIONS III, 2001, 4209 : 124 - 131
  • [29] Resource allocation for real-time traffic in unreliable wireless cellular networks
    Xu, Jun
    Guo, Chengcheng
    Zhang, Hao
    Yang, Jianfeng
    [J]. WIRELESS NETWORKS, 2018, 24 (05) : 1405 - 1418
  • [30] Hybrid FEC/ARQ Schemes for Real-Time Traffic in Wireless Networks
    Jalil, Samia
    Abbad, Mohammed
    El Azouzi, Rachid
    [J]. 2015 INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS AND MOBILE COMMUNICATIONS (WINCOM), 2015, : 134 - 139