Real-time detection of traffic anomalies in wireless mesh networks

被引:6
|
作者
Zaidi, Zainab R. [1 ,5 ]
Hakami, Sara [2 ,4 ]
Landfeldt, Bjorn [3 ,4 ]
Moors, Tim [2 ]
机构
[1] Networked Syst Grp, NICTA, Alexandria, NSW 1435, Australia
[2] UNSW, Sch EE&T, Sydney, NSW 2052, Australia
[3] USyd, Sch IT, Sydney, NSW 2006, Australia
[4] NICTA, Alexandria, NSW, Australia
[5] George Mason Univ, Network Architecture Lab, Fairfax, VA 22030 USA
关键词
Anomaly detection; Wireless mesh networks; Principal component analysis; Chi-square statistics; Denial-of-service; Port scan;
D O I
10.1007/s11276-009-0221-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Anomaly detection is emerging as a necessary component as wireless networks gain popularity. Anomaly detection has been addressed broadly in wired networks and powerful methods have been developed for correct detection of a variety of known attacks and other anomalies. In this paper, we propose a real-time anomaly detection and identification scheme for wireless mesh networks (WMN) using components from previous methods developed for wired networks. Experiments over a WMN testbed show the effectiveness of the proposed scheme in isolating different types of anomalies, such as Denial-of-service attacks, port scan attacks, etc. Our scheme uses Chi-square statistics and it is based on similar ideas as the scheme presented by Lakhina et al. although it has lower computational complexity. The original method by Lakhina et al. was developed for wired networks and used Principal Component Analysis (PCA) for reducing the dimensions of observed data and Hotelling's t (2) statistics to distinguish between normal and abnormal traffic conditions. However, in our studies we found that dimension reduction is the most computationally intensive process of the scheme. In this paper we propose an alternative way of reducing dimensions using flow variances in a Chi-square test. Experimental results show that the Chi-square test performs similarly well to the PCA-based method at merely a fraction of the computations. Moreover, we propose an automatic identification scheme to pin-point the cause of the detected anomaly and its contribution in terms of additional or lack of traffic. Our results and comparison with other statistical tools show that the Chi-square test and the PCA-based method with identification scheme make powerful tools for real-time detection of various anomalies in an interference prone wireless networking environment.
引用
收藏
页码:1675 / 1689
页数:15
相关论文
共 50 条
  • [41] Real-time forest fire detection with wireless sensor networks
    Yu, LY
    Wang, N
    Meng, XQ
    [J]. 2005 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING PROCEEDINGS, VOLS 1 AND 2, 2005, : 1214 - 1217
  • [42] Convolutional Neural Networks for Real-Time and Wireless Damage Detection
    Avci, Onur
    Abdeljaber, Osama
    Kiranyaz, Serkan
    Inman, Daniel
    [J]. DYNAMICS OF CIVIL STRUCTURES, VOL 2, IMAC 2019, 2020, : 129 - 136
  • [43] Real-time and Passive Wormhole Detection for Wireless Sensor Networks
    Luo, Guoxing
    Han, Zhigang
    Lu, Li
    Hussain, Muhammad Jawad
    [J]. 2014 20TH IEEE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2014, : 592 - 599
  • [44] Real-time traffic in deflection networks
    Olesinski, W
    Gburzynski, P
    [J]. PROCEEDINGS OF THE COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS MODELING AND SIMULATION (CNDS'98), 1998, : 23 - 28
  • [45] QoS and energy aware routing for real-time traffic in wireless sensor networks
    Mahapatra, A
    Anand, K
    Agrawal, DP
    [J]. COMPUTER COMMUNICATIONS, 2006, 29 (04) : 437 - 445
  • [46] Randomized Scheduling of Real-Time Traffic in Wireless Networks Over Fading Channels
    Tsanikidis, Christos
    Ghaderi, Javad
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2023, 31 (04) : 1688 - 1701
  • [47] An expert system for real-time traffic management in wireless local area networks
    Frantti, T.
    Majanen, M.
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (10) : 4996 - 5008
  • [48] CAPEL: A packet discard policy for real-time traffic over wireless networks
    Yuen, Ching-Wan
    Lau, Wing-Cheong
    Yue, On-Ching
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-14, 2007, : 158 - 163
  • [49] ARC: The analytical rate control scheme for real-time traffic in wireless networks
    Akan, OB
    Akyildiz, IF
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2004, 12 (04) : 634 - 644
  • [50] A new channel allocation scheme for real-time traffic in wireless cellular networks
    Chaudhary, Vineet
    Tripathi, Rajeev
    Shukla, N. K.
    Nasser, Nidal
    [J]. 2007 IEEE INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE, VOLS 1 AND 2, 2007, : 551 - +