DOS Attack Source Localization in MANET
DOS Attack Source Localization in MANET
Abstract—We consider a credible routing in Ad Hoc network Ad Hoc network faces a lot of security threat, especially the
for DOS attack problems. This paper presents a probabilistic denial of service (DOS) attack, attack and shorter launch time
packet marking location technology, describes the source packet will cause serious consequences, and the serious
marking attack node localization method, and here we build the consequences is becoming more and more short, the time
attack source reliable positioning model based on probabilistic interval in Ad Hoc network security management, therefore, it
packet marking. In this case, we provide that the data source in
need to “rapid positioning, timely detection, real time to
Ad Hoc network can back and transmission path can restore, it
can be tracked by some behavior of the network user node, prevent” network attacks, but previous attack detection
[5]
information of the sender, forwarding and receiver can deny method cannot meet its security requirements . We use
that the occurrence of data exchange. We also verified the statistical methods, in a relatively short period of time
relationship between the success rate of packet marking processing a large amount of data, through statistical results,
probability and location. The simulation results show that this [6]
we can implement preparedness and accurate positioning .
method is found in destination node after the DOS attack can The importance of network security management principle is
date back to the location of the attack source actively.
“as close to attack the source of, the higher the efficiency of
I. INTRODUCTION the detection”. Therefore, the latest idea we prevent DOS
[7-8]
Mobile Ad Hoc Networks (MANET) is a new type of attacks is “blocking attacks from fountainhead” approach .
self-organizing distributed wireless network which is Especially, dealing with distributed attacks from the attack of
multi-hop, no center and not dependent on any fixed the block is the most effective means of protection.
infrastructure. MANET is able to apply to both the military Now most anomaly detections focus on traditional IDS
[1] detection, the domestic and international proposed many
and civilian fields . But the security and reliability of [9]
network communication of mobile Ad Hoc networks face methods, such as artificial intelligence method , statistical
[10] [11] [12]
great challenges due to the dynamic topology mobile nodes. method , neural network methods and agent method ,
The traditional security technologies, such as confidentiality etc. An intruder behavior is different from normal behavior
and authentication, do not resolve the security issues of the Ad that is a basic assumption of anomaly detection, by way of the
Hoc networks. Based on the observation on the node behavior, establishment of a normal user behavior model, most anomaly
peoples began to study trusted routing technology based on detection system check the current conflict behavior and
trust mechanism, in which the trust of the routing is enhanced normal behavior, therefore determines behavior of users and
by introducing the trust level to the nodes. However, in this found the attack.. But trust mechanism introduction of trusted
method, there are many problems to be solved such as the routing, routing behavior is almost no further mining. In fact,
complexity of the collection and calculation of the trust of the the trust mechanism in routing is still affected by the attacks;
nodes, the high network overhead, some of the abnormal influence the credibility of the node, etc.
behavior not being found in time, malicious behavior like gray In this paper, the main contributions of our work include:
hole not being completely avoided and trust conspiracy (1) We put forward the packet marking source attack node
[2-4]
existing . In this paper we will research the detection localization method.
method of the abnormal behavior in trusted routing of (2) Furthermore, we extend the attack source reliable
MANET to solve the above problem. positioning model based on probabilistic packet marking. In
this case, we give a method that can trace the location of the
attack source actively after the DOS attacks is found in
destination node.
*Resrach supported by Foundation project: regional air defense network Based on the above requirements and design concept, it is
reliability assessment method research project (JC03130301)
A. Heliu, Ph.D, her research direction is equipment information security,
proposed in this paper that based on the probabilistic packet
Missile Institute, Air Force Engineering University, Xi’an, 710051 China marking attack source location technology, mainly for mobile
(phone:18629058656; e-mail: hilling668@[Link]). Ad Hoc network anomaly traffic detection of DOS attack and
B. Yingjun Zhao, Professor Ph.D, research direction is Support and attacks the source localization problem.
evaluation of equipment system, Missile Institute, Air Force Engineering
University, Xi’an, 710051 China.
C. Qingkuan Dong is associate professor, his research direction is
Network information security. Communication Engineering, Xi'an
University of Electronic Science and Technology 710071, China (e-mail:
qkdong@[Link])
978-1-4673-8318-9/16/$31.00©2016 IEEE
25
II. MAIN RESULTS B. DOS attack source tag process and transmit positioning
Due to the source of DOS attack distributed in different
A. The attack source localization technology based on locations of Ad Hoc networks, it can determine relatively
probabilistic packet marking model hidden attack easily and take blocking measures for each
When or after the DOS attack happens, IP trackback attack source that carry out the distributed data collection and
algorithm that can find the attacker location is designed correlation calculation based on the source attack location of
through the existing information detects the attack paths. probabilistic packet marking method. Thus the process what
Based on the DOS attack network structure, it can be divided discuss above will guarantee the normal work of the whole Ad
into the position of attack network, users, etc. Based on the Hoc network.
DOS attack network structure, we divided that into position to (1) The labeling
attack network and attack users, etc. Since most of the attacks IP packet
source addresses are randomly generated pseudo, therefore,
attack source location technology difficulty is hard to
pinpoint.
This paper provides probabilistic packet marking Extract the package
location technology, ensures that the data source in Ad Hoc < source IP, source
link layer address >
network can back and transmission path can restore, it can be address mapping
tracked by some behavior of the network user node,
information of the sender, forward and receiver can deny data
Mapped to the
exchange. In the data receiving end, the router ID information corresponding
Mark operation
carried by extracting the marked packets that can directly connection
positioning on the successful connection has been established
to source side closest router; If positioning failure, use
By The router ID and
probabilistic packet logging information that is stored in the Packet sampling signature information
sampling
process of reverse path reconstruction, and also restore the in PM
to
tag attached to the
message
transmission path and find the nearest the source side of the
router. Have not been to sampling
Transmit positioning system is shown in Figure 1:
node
26
multi-node event correlation, finally multiple nodes “joint
action” against attack, it is based on the probabilistic packet
marking attack source localization technology at the core of
the thought.
III. SIMULATIONS
This paper uses simulation tools for Matlab2012. In order
to simulate reality as much as possible that exist in a variety of
Ad Hoc network attack, when attacking simulation, according
to the different number and the distribution in attack of the
source and the victims, corresponding to build the three attack
scenarios, respectively is: single attack source/victim scenario,
attack victims source/single scenario and attack scenario
source/victims. Monophyletic attack can be simplified
terminal for victims of the attack source to stream of data
packets.
multiple data sources link layer address can find by the query Is it the
Is it set to
matching process; attack?
attack
packet?
Step Ļ : “Package marking node” reply message to
transmit positioning control return locating results, after Yes Yes
transmit positioning control receiving the corresponding Ad Notify the
Attacks on
positioning reply message, and then forward it to transmit package Hoc
source
location
labels Network
positioning detection. system
27
B. A DOS attack detection simulation results: location to find the source of attack the possibility of success.
i. The edge of the single source of attack scenarios By Fig.5 you can see, the success rate of single attack source
probabilistic packet marking mechanism simulation packet marking mechanism of PS is marking probability PM
The success of transfer of a probabilistic packet marking increasing function, and the growth rate decreases with the
positioning is mainly related to marking probability, attacks increase of the PM. This means that when marking probability
the package number, and it has nothing to do with factors such PM increases to a certain degree, the success rate will be
as network traffic, the hop, etc. So, in single attack approaching a gradual value, the value is 100%; At this point,
source/victim attack scenario, by the simulation experiments continuing to increase the PM will not cause significant impact
on the fringes of probabilistic packet marking mechanism, we to the success. Marking probability is not, therefore, the
inspect packet marking probability and the number of attack bigger the better, choose an appropriate probability PM is to
packets for its transmit positioning success rate. use packet marking positioning mechanism is the key.
Adjusting the packet marking probability PM, document ii. Attack source packet marking mechanism of scene
transfer under different packet marking probability simulation:
positioning results, the simulation process of other parameters Victims in the attack source/single attack scenario, by the
are fixed. For every 25 PM simulation, statistics of the number simulation experiments on the fringes of probabilistic packet
of successful track (assuming for m), is the success rate of marking mechanism, we inspect packet marking probability
m/25. The simulation environment and the parameter is set to: for its transmit positioning success rate.
Scenario name: Single Mark, medium scale, including an At the beginning of the simulation, the entire attack source
attack terminals, terminal 1 was attacked, 100 attack packets; at a constant rate at the same time sends attack packets to be
Packet marking probability PM 0.02 is the biggest probability, attacked source. Upon receipt of attack packets attack end,
minimum probability is 0.002, the step length is [Link] issue a request to transmit positioning corresponding transfer
simulation results are shown in Figure 5: location server, location server to initiate the transmission
transfer location process. In this simulation, the test packet
marking probability of marginal probability packet marking
mechanism positioned affect the success rate of attacks end.
Adjust the packet marking probability PM, then record the
results under different packet marking probability transfer
location, the other parameters in the simulation process fixed.
For each of the 25 PM simulation, assume that the first time i
tracked down the mi attack source, i =1,2,Ă,10, a total of m
attack source, the average success rate is:
25 25
(¦ mi ) / 25 (¦ mi ) /( 25m)
i 1 m i 1 (2)
PS=1ˉ(1ˉPM)N (1)
Among them, the PM said packet marking probability. Thus
it can be seen that the success rate of single attack source
packet marking mechanism are only related with the marking
probability, the number of attack packets, and has nothing to
do with the network size. In fact, according to the mechanism
of packet marking scheme, once an attack package is marked,
the victim has been detected as well as traced to the attack
source, this reverse tracking process does not exist any
uncertainty, it is completely sure. This means that the bag tag
positioning mechanism success depends entirely on attack
probability of packet is marked on the router, once a package
is marked can find the source of the attack. Single attack Figure 6. Attack source scene package mechanism
source packet marking the success rate of said a bag tag marking probability and the success rate
28
The PM instead packet marking probability. Assuming that REFERENCES
the victims were detected N attack packets, the success rate of [1] Elsalih M, Shen Xuemin. Stimulating Cooperation in Multi-hop
single attack source packet marking mechanism theory is: Wireless Networks Using Cheating Detection System[C]//Proc. of
INFOCOM’10. San Diego, USA: [s. n.], 2010.
P=1ˉ(1ˉPM)N (3) [2] Crosbie M, Spaford EˊDefending a computer system using
autonomous agents[C]ˊIn: Proceedings of the 18th National
Suppose there are n source of attack, the attack source Information Systems Security Conference, 1995.
packet marking mechanism theory success rate is: [3] Boukerche A, Turgut B, Aydin N, et al. Routing Protocols in Ad Hoc
Networks: A Survey[J]. Computer Networks, 2011, 55(13): 3032-
n 3080.
i n i
PS ¦ n C P (1 P)
i
n
i
[4] Animesh PatchaˊAn over view of anomaly detection techniques:
i 1 (4) Existing solution And latest technological trendsˊComputer
Networks, 2007, 51(12): 3448~3470.
It assumes that all attack source at the same attack packets, [5] YˊGuan, AˊGhorbani, NˊBelacelˊY-Means: A Clustering
the same are in N. However, by mathematical deduction Method for Intrusion DetectionˊIn: Proceedings of Canadian
shows: Conference on Electrical and Computer EngineeringˊMontreal,
n Canada: 2003, 1083~1086.
i n i
PS ¦nCi 1
i
n P (1 P)
i [6] Wang lina, Xu Wei Liu Zhu. Clustering analysis method based on
similarity of anomaly intrusion detection system model and
n implementation. Small micro computer system,2004ˈ25(7)˖
i n! n i
¦
i 1 n ( n 1)!i!
P (1 P)
i
1333~1336.
[7] Sharma PˈTrivedi P Aˊ An Approach to Defend Against Wormhole
n
( n 1)! n i Attack in Ad Hoc Network Using Digital Signature˷C ˹/ /Proceedings
¦ (n 1)!(i 1)! P (1 P)
i 1
i
of the 3rd IEEE International Conference on Communication Software
and Networksˊ Washington Dˊ CˊˈUSA: IEEE Computer
n n i
¦C
i 1
i 1
n 1 P (1 P)
i Societyˈ 2011: 307-311.
[8] Hehui, hong-li zhang. A DDOS attack detection method based on
n
similarity. Journal of communication, 2004ˈ25(7)˖174~184.
n i
P ¦ C in11 P i 1 (1 P) [9] Saizhe Zuo. The trust values of the updated model on the basisof the
i 1 principle of memory. The 7th national conference on computer
supported cooperative work and the fifth national conference on
P [ P (1 P )]n 1 intelligent information network, conference papers,2010.
P [10] Xiong Ping. Adaptive anomaly detection method based on normal
profile update. Journal of wuhan university (information science
(5)
edition),2007ˈ32(9)˖842~845.
[11] Abbes T, Bouhoula A, Rusinowitch MˊProtocol analysis in intrusion
detection using decision treeˊIn: Proceeding of the International
Conference 011 Information Technology: Coding and
IV. CONCLUSIONS Computing(ITCC’04)ˊLos Alamitos: USAˊIEEE Computer Society
This paper proposes a method of attack source localization pressˈ2004ˈ404~409.
[12] Soufiene D. Mitigating Packet Dropping Problem in Mobile Ad Hoc
technology based on probabilistic packet marking that based Networks: Proposals and Challenges[J]. IEEE Communications
on DOS attack in the Ad Hoc network. Accurately and timely Surveys & Tutorials, 2011, 13(4): 658-672.
find attacks, the way of “from a source block the attack” is the
newest concepts of preventing DOS attacks. Especially in
dealing with distributed attacks, the most effective means of
protection is blocking from attack. Actually, the real Ad Hoc
network nodes environment behavior is complicated,
completing description and identification of the behavior of
all nodes is impossible, so the model of this paper have
limitations. The next steps we will be the perfect location
model, further improvements in the similarity factors
subdivision node connection, make the model easier on the
implementation of the project.
ACKNOWLEDGMENT
This work was supported by Research Projects of Regional
Air Defense Network Reliability Evaluation Method of China
under Grant JC03130301.
29