Skip to main content
QUICK REVIEW

[논문 리뷰] Intrusion Detection In Mobile Ad Hoc Networks Using GA Based Feature Selection

Rajarathnam Nallusamy, K. Jayarajan|arXiv (Cornell University)|2009. 12. 15.
Network Security and Intrusion Detection참고 문헌 12인용 수 5
한 줄 요약

이 논문은 모바일 애드 hoc 네트워크(MANETs)에서 침입 탐지에 대해 유전 알고리즘(GA) 기반 특성 선택 방법을 제안하며, 베이지안 네트워크를 활용해 특성의 관련성을 최적화하고 탐지 정확도를 향상시킨다. 이 방법은 부용한 특성을 감소시켜 기존 마르코프 블랭킷 기반 선택 대비 더 높은 탐지율과 낮은 오류 경고를 달성한다.

ABSTRACT

Mobile ad hoc networking (MANET) has become an exciting and important technology in recent years because of the rapid proliferation of wireless devices. MANETs are highly vulnerable to attacks due to the open medium, dynamically changing network topology and lack of centralized monitoring point. It is important to search new architecture and mechanisms to protect the wireless networks and mobile computing application. IDS analyze the network activities by means of audit data and use patterns of well-known attacks or normal profile to detect potential attacks. There are two methods to analyze: misuse detection and anomaly detection. Misuse detection is not effective against unknown attacks and therefore, anomaly detection method is used. In this approach, the audit data is collected from each mobile node after simulating the attack and compared with the normal behavior of the system. If there is any deviation from normal behavior then the event is considered as an attack. Some of the features of collected audit data may be redundant or contribute little to the detection process. So it is essential to select the important features to increase the detection rate. This paper focuses on implementing two feature selection methods namely, markov blanket discovery and genetic algorithm. In genetic algorithm, bayesian network is constructed over the collected features and fitness function is calculated. Based on the fitness value the features are selected. Markov blanket discovery also uses bayesian network and the features are selected depending on the minimum description length. During the evaluation phase, the performances of both approaches are compared based on detection rate and false alarm rate.

연구 동기 및 목표

  • 모바일 애드 hoc 네트워크(MANETs)가 개방된 매체와 동적 토폴로지로 인해 공격에 취약한 점을 해결하기 위해.
  • 감사 데이터의 부용하거나 관련성이 없는 특성을 줄임으로써 침입 탐지 시스템(IDS) 성능을 향상시키기 위해.
  • 베이지안 네트워크 프레임워크 내에서 유전 알고리즘(GA)과 마르코프 블랭킷 탐지 기반의 특성 선택 기법의 효과성을 비교하기 위해.
  • MANET의 이상 기반 침입 탐지에서 탐지율을 최적화하고 오류 경고율을 최소화하기 위해.

제안 방법

  • 정상 및 비정상 네트워크 행동을 모델링하기 위해 다양한 공격을 시뮬레이션한 후 모바일 노드에서 감사 데이터를 수집한다.
  • 수집된 특성 위에 베이지안 네트워크를 구축하여 특성 간의 확률적 종속성을 모델링한다.
  • 베이지안 네트워크에서 유도된 적합도 함수를 최대화함으로써 최적의 특성 부분집합을 찾기 위해 유전 알고리즘(GA)을 적용한다.
  • 마르코프 블랭킷 탐지에서 최소 기술 길이(MDL) 원리를 사용하여 예측 정확도를 유지하면서 가장 관련성이 높은 특성을 식별한다.
  • 탐지율과 오류 경고율을 성능 지표로 삼아 두 방법을 평가한다.
  • 이상 탐지에서 GA 기반 및 마르코프 블랭킷 기반 특성 선택의 탐지 성능과 효율성을 비교한다.

실험 결과

연구 질문

  • RQ1유전 알고리즘 기반 특성 선택은 기존 방법에 비해 MANET에서 침입 탐지 성능을 어떻게 향상시키는가?
  • RQ2GA 기반 및 마르코프 블랭킷 기반 특성 선택의 상대적 효과성은 오류 경고를 줄이고 탐지율을 높이는 데서 어떻게 나타나는가?
  • RQ3어느 특성 부분집합 선택 방법이 MANET의 이상 탐지에서 감사 데이터의 예측 능력을 더 잘 유지하는가?
  • RQ4부용하거나 관련성이 없는 특성은 모바일 애드 hoc 네트워크의 침입 탐지 시스템 성능을 어느 정도 악화시키는가?

주요 결과

  • 유전 알고리즘 기반 특성 선택 방법은 마르코프 블랭킷 탐지 방법보다 더 높은 탐지율을 달성했다.
  • GA 기반 방법은 낮은 오류 경고율을 기록하여 실제 공격를 정확하게 식별하는 데 있어 정밀도가 향상됨을 시사한다.
  • 베이지안 네트워크를 활용한 특성 선택은 탐지 정확도를 훼손하지 않으면서 감사 데이터의 차원을 크게 감소시켰다.
  • 마르코프 블랭킷 탐지 방법은 효과적이었지만, 침입 탐지의 적합도 함수 최적화에 있어 효율성이 떨어졌다.
  • 두 방법 모두 부용한 특성의 영향을 줄였지만, 평가 결과 GA 기반 접근법이 전체적으로 뛰어난 성능을 보였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.