摘要
特征检测是传感器网络中一种常用的入侵检测手段,针对入侵检测是否有效,在很大程度上取决于IDS模块的布置。现有IDS模块布置策略可能出现汇聚节点被淹没、网络资源利用率低、以及检测效率低等问题。为了提高检测精度,提出IDS优化布置算法,根据图论中最小割集和最小支配集的概念,把入侵检测模块布置在最小割集的传感器节点上,并通过图论中的最大流来实现最小割集的求解问题。最后通过仿真论证,根据特征检测的IDS布置算法进行仿真。结果表明,与随机布置算法相比,优化布置算法不仅提高检测率,具有良好的收敛性,而且使网络资源的利用效率也大为提高。
Signature-based detection is the mainstay of operational intrusion detection systems in wireless sensor networks.The effectiveness of the signature based intrusion detection techniques depends critically on the placement of the detection modules.Some problems may exist in current strategies,such as the overwhelming of a single sink node,resource usage,as well as the inefficiency.By means of minimum cut-sets,minimum dominating sets in Graph Theory,an optimal Placement strategy of signature-based Intrusion Detection Modules was proposed in this paper.The proposed algorithms,based on the concepts of minimum cut-set and minimum dominating set,enabled the intrusion detection functionality on particular sensor nodes.According to max-flow,minimum cut-sets computation problem was solved.The algorithm performance in identifying intrusions using signature-based detection techniques was studied via simulations.Results showed that the optimal Placement algorithm,compared with Random Placement algorithm,can improve detection rate and converge very well,and the utilization of network resources was also greatly enhanced.
出处
《计算机仿真》
CSCD
北大核心
2011年第6期136-140,295,共6页
Computer Simulation
关键词
特征检测
入侵检测系统模块
最小割集
最小支配集
最大流
算法仿真
Signature detection
Intrusion detection system(IDS) module
Minimum cut-Set(MCS)
Minimum dominating-set
Max-flow
Algorithm simulation