Special Issue Paper
DISA: Detection and isolation of sneaky attackers in locally monitored multi-hop wireless networks
Article first published online: 13 OCT 2009
Copyright © 2009 John Wiley & Sons, Ltd.
Security and Communication Networks
Volume 6, Issue 12, pages 1524–1538, December 2013
How to Cite
Khalil, I., Bagchi, S., AbuAli, N. and Hayajneh, M. (2013), DISA: Detection and isolation of sneaky attackers in locally monitored multi-hop wireless networks. Security Comm. Networks, 6: 1524–1538. doi: 10.1002/sec.152
- Issue published online: 13 OCT 2009
- Article first published online: 13 OCT 2009
- packet dropping;
- multi-hop wireless networks;
- local monitoring;
- transmission power control;
- malicious collusion
Local monitoring has been demonstrated as a powerful technique for mitigating security attacks in multi-hop ad hoc networks. In local monitoring, nodes overhear partial neighborhood communication to detect misbehavior such as packet drop or delay. However, local monitoring as presented in the literature is vulnerable to a class of attacks that we introduce here called stealthy packet dropping. Stealthy packet dropping disrupts the packet from reaching the destination by malicious behavior at an intermediate node. However, the malicious node gives the impression to its neighbors that it performed the legitimate forwarding action. Moreover, a legitimate node comes under suspicion. We introduce four ways of achieving stealthy packet dropping, none of which is currently detectable. We provide a protocol called DISA, based on local monitoring, to remedy each attack. DISA incorporates two techniques—having the neighbors maintain additional information about the routing path, and adding some checking responsibility to each neighbor. We show through analysis and simulation that basic local monitoring (BLM) fails to efficiently mitigate any of the presented attacks while DISA successfully mitigates them. Copyright © 2009 John Wiley & Sons, Ltd.