Intrusion detection for secure communications in data networks데이터 망에서 안전한 통신을 위한 침입탐지 기법에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 657
  • Download : 0
DC FieldValueLanguage
dc.contributor.advisorKim, Se-hun-
dc.contributor.authorLee, Keun-Soo-
dc.description학위논문(박사) - 한국과학기술원 : 산업공학과, 2008.2, [ iv, 82 p. ]-
dc.description.abstractGuaranteeing secure and reliable communications in wireless and wired networks is very important in recent and future networks. In this thesis, we propose effective defense schemes to protect wireless adhoc network and wired networks from illegal intrusions. Wireless mobile adhoc networks (MANETs) have many applications to the environments where creating fixed infrastructure is prohibitive. However, as the medium is easily monitored, the topology of the network is dynamic, the networking protocols rely on distributed cooperation of the nodes, and the nodes have constrained capabilities, MANETs are particularly vulnerable to intrusions, especially to sinkhole intrusion. The sinkhole intrusion redirects all routes in the networks to a sinkhole node to do malicious behaviors. In this thesis, we propose an efficient method for sinkhole intrusion detections in MANETs using Dynamic Source Routing (DSR) protocol. The proposed method uses the route record of transmitted route request messages for detection, and removes the identified attack node from the network. Through the computer simulations, we show that the proposed method has better performance than other sinkhole detection methods in terms of detection rate, detection time, and energy consumption. Another issue dealt with in the thesis is a scheme to defend against service denial attacks in large scale networks. Distributed Denial of Service (DDoS) attack causes very serious problems to availability or stability of the Internet. A very large number of compromised agent hosts which are distributed widely on the Internet generate enormous volume of traffic to a target system to prohibit providing services. As they spoof the source IP address of their packets, it is very difficult to trace them. All systems connected to the Internet can be a victim although they are well-equipped in security. In this thesis, an effective defense scheme is proposed. Unlike other methods, source IP spoofing feature is adopte...eng
dc.subjectmobile adhoc network-
dc.subjectsinkhole attack-
dc.subjectdistributed denial of service attack-
dc.subjectself-organizing map neural network model-
dc.subject이동성 에드혹 네트워크-
dc.subjectsinkhole 공격-
dc.subject분산서비스 거부 공격-
dc.subject자기 조직화 맵 신경망 모델-
dc.subjectmobile adhoc network-
dc.subjectsinkhole attack-
dc.subjectdistributed denial of service attack-
dc.subjectself-organizing map neural network model-
dc.subject이동성 에드혹 네트워크-
dc.subjectsinkhole 공격-
dc.subject분산서비스 거부 공격-
dc.subject자기 조직화 맵 신경망 모델-
dc.titleIntrusion detection for secure communications in data networks-
dc.title.alternative데이터 망에서 안전한 통신을 위한 침입탐지 기법에 관한 연구-
dc.identifier.CNRN295316/325007 -
dc.description.department한국과학기술원 : 산업공학과, -
dc.contributor.localauthorKim, Se-hun-
Appears in Collection
Files in This Item
There are no files associated with this item.


  • mendeley


rss_1.0 rss_2.0 atom_1.0