摘要
提出了无线传感器网络(WSN)中一种防御攻击的分布式入侵检测系统,包括以数据采集、处理和传输为目的的3层分层的体系结构和基于异常的分布式入侵检测算法.本地入侵检测系统(IDS)依附于WSN的每一个节点,其作用是采集网络运行的原始数据,以及计算本地异常指数,以此衡量当前节点的运行与正常运行情况之间的差别.在簇头和管理节点两个层次中进行异常指数的融合,分别形成簇级和网络级的异常指数.对融合算法进行了数学描述和理论推导,通过仿真并借助接受者操作特性(ROC)曲线,对节点、簇头和管理节点的运行情况进行了性能评估,总体结果证实了体系结构和算法的有效性.研究表明,这种融合算法能大幅提高系统的检测概率.
A distributed intrusion detection system against attacks in wireless sensor networks (WSN) was presented, including a three-level hierarchical architecture for data collection, processing and transmission. A distributed anomaly-based intrusion detection algorithm was also proposed, Local IDS (intrusion detection systems) were attached to each node of the WSN, which were responsible for collecting raw data of network operation, and computing a local anomaly index, measuring the difference between the current node operation and normal operation. In this hierarchical system, node-level and cluster-level anomaly index were fused, producing cluster-level and network-level anomaly index respectively. The fusion algorithm was described mathematically and deduced theoretically. For performance evaluation,the ROC (receiver operating characteristics) curves in simulation, for operations at the nodes, cluster heads and managers,was adop ed. The overall results confirm the effectiveness of the architecture and algorithm described in the paper. Research shows that the fusion algorithm can greatly improve system's probability of detection.
出处
《华中科技大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2009年第9期49-52,共4页
Journal of Huazhong University of Science and Technology(Natural Science Edition)
基金
教育部985重点工程资助项目
关键词
无线传感器网络
分布式入侵检测系统
融合算法
体系结构
异常
接受者操作特性
wireless sensor networks
distributed intrusion detection systems
fusion algorithm
architecture
anomaly
receiver operating characteristics (ROC)