移动AdHoc网的典型网络攻击与防范

矿产资源开发利用方案编写内容要求及审查大纲
矿产资源开发利用方案编写内容要求及《矿产资源开发利用方案》审查大纲一、概述
㈠矿区位置、隶属关系和企业性质。

如为改扩建矿山, 应说明矿山现状、
特点及存在的主要问题。

㈡编制依据
(1简述项目前期工作进展情况及与有关方面对项目的意向性协议情况。

(2 列出开发利用方案编制所依据的主要基础性资料的名称。

如经储量管理部门认定的矿区地质勘探报告、选矿试验报告、加工利用试验报告、工程地质初评资料、矿区水文资料和供水资料等。

对改、扩建矿山应有生产实际资料, 如矿山总平面现状图、矿床开拓系统图、采场现状图和主要采选设备清单等。

二、矿产品需求现状和预测
㈠该矿产在国内需求情况和市场供应情况
1、矿产品现状及加工利用趋向。

2、国内近、远期的需求量及主要销向预测。

㈡产品价格分析
1、国内矿产品价格现状。

2、矿产品价格稳定性及变化趋势。

三、矿产资源概况
㈠矿区总体概况
1、矿区总体规划情况。

2、矿区矿产资源概况。

3、该设计与矿区总体开发的关系。

㈡该设计项目的资源概况
1、矿床地质及构造特征。

2、矿床开采技术条件及水文地质条件。

合集下载

Ad Hoc网络洪泛攻击防御的研究

Ad Hoc网络洪泛攻击防御的研究

Ad Hoc网络洪泛攻击防御的研究摘要:针对移动Ad Hoc网络反应式路由的洪泛攻击,分析了现有的抵御洪泛攻击的FAP方案的安全漏洞,提出了一种简单易行的CSR方案,并与FAP方案进行了对比。

关键词:移动Ad Hoc网络反应式路由洪泛攻击 FAP方案移动Ad Hoc网络是一种新型的移动多跳无线网络,它不依赖于任何固定的基础设施和管理中心,而是通过传输范围有限的移动节点间的相互协作和自我组织来保持网络连接并实现数据的传递。

Ad Hoc网络中路由的特殊性使其成为Ad Hoc网络中的重要问题,一直是该领域的研究热点。

目前,较为成熟且已在Ad Hoc网络中广为使用的路由协议路由协议有优化链路链路状态路由算法OLSR(Optimized Link State Routing Protocol)、动态源路由DSR(Dynamic Source Routing)、按需距离矢量路由AODV (Ad Hoc On-Demand Distance Vector Routing)等。

同时,随着各类攻击的出现,基于安全的Ad Hoc路由协议也相继产生[1~4]。

洪泛攻击是新近提出的一种针对Ad Hoc网络中反应式路由的攻击类型,分为RREQ报文和数据报文攻击两种。

它通过在网络中引发拒绝服务,能够对现有的所有反应式路由进行攻击。

Ping Yi等人首次提出了这种攻击的模型[5],同时给出了抵御这种攻击的洪泛攻击预防FAP (Flooding Attack Prevention)方案。

针对FAP方案的不足,本文提出了通信状态记录CSR (Communication Status Record)方案。

该方案中各节点通过实时记录与其相关联的节点及链路的状态,从而可以有效地辨别非法节点,避免为非法节点转发报文,达到抵御洪泛攻击的效果。

1 背景知识1.1 反应式路由简介反应式路由协议又称为按需路由协议,是一种当需要发送数据时才查找路由的路由算法。

移动Ad hoc网络中的安全问题

移动Ad hoc网络中的安全问题
等 ,并 且 在 此 基 础 上 提 出 了 相 关 的安 全 策 略 ,如 加 限 非 常 模 糊 。 这 样 一 来 , 防 火 墙 技 术 不 再 适 用 于
密 、认 证 、访 问 控 制 和权 限 管理 、防 火 墙 等 。
而 在 A o dh c网络 中 没 有 基 站 或 中 心 节 点 ,所
o 络 ,与 传 统 的无 线 网络 有 很 大 不 同 。它 不 依 赖 于 任 适 用 于 Adh c网络 ,主要 表 现 在 以下 三 个 方 面 。
何 固 定 的基 础 设 施 和 管 理 中 心 ,而 是 通 过 传 输 范 围
( 1)传 统 网 络 中 的 加 密 和 认 证 通 常 包 括 一 个
维普资讯 http:/ຫໍສະໝຸດ
移 动 Ad h e网络 中 的 安 全 问 题 o
王 海 涛 郑 少仁
( 解放 军理T 大学 通信 工程 学 院 南京 2 0 0 10 7)
A o dh c网 络 作 为 一 种 新 型 的 移 动 多 跳 无 线 网 了在 传 统 网络 中能 够 较 好 工 作 的 安 全 机 制 可 能 不 再
相 应 的安 全 策 略 和 措 施 。
( 2)传 统 网 络 可 以使 用 防 火 墙 技 术 来 保 护 网
络 内部 与 外 界 通 信 时 的 安 全 。 由 于 所 有 进 出该 网 络
1 A o Oh e网 络 面 临 的 安 全 问 题
的数 据 都 通 过 一 个 节 点 ,例 如 某 个 服 务 器 ,防 火 墙
便 ,构 造 成 本 较 低 ,它 正 逐 渐 地 运 用 于 商 业 和 民用 家 彼 此 信 任 的 前 提 下 工 作 。 而 Adh c网 络 缺 乏 足 o 环 境 。 但 目前 在 商 用 环 境 中运 用 Adhc网 络 面 临 够 的物 理 保 护 ,没 有 中心 节 点并 且 节 点 的 计 算 能 力 o 的一 个 重要 问 题 就 是 它 更 易 受 到 各 种 安 全 威 胁 和 攻 很 低 ,这使 得 传 统 的 加 密 和 认 证 机 制 无 法 在 A o dh c 击 ,包 括被 动 窃 听 、伪造 身 份 、拒 绝 服 务 等 。 本 文 网络 中实 现 。 将 主 要 探 讨 A o dhc网 络 中所 面 临 的 安 全 问 题 以 及

AdHoc无线网络虫洞攻击的安全策略

AdHoc无线网络虫洞攻击的安全策略

Information Security •信息安全Electronic Technology & Software Engineering 电子技术与软件工程• 169【关键词】Ad Hoc 无线网络 虫洞攻击 安全策略虫洞攻击是针对Ad Hoc 无线网络路由协议的高级攻击形式,通常情况下,这种攻击方式是由两个以上的恶意节点相互合作共同发起攻击,在攻击过程中,两个恶意节点距离较远,但是二者间却如同一步之遥,它所发生的攻击频率与机率甚至比正常路径的跳跃数还要短,因此,对虫洞攻击的防御难度系数大,对防御技术要求高。

1 Ad Hoc无线网络的组成框架与特性Ad Hoc 无线网络的组成框架可以分为两种,一种是对等式平面结构,另一种是分级结构,对等式平面结构中所有的网络节点地位平等,而分级结构中,网络是以簇为子网构成的。

目前,Ad Hoc 无线网络正逐步呈现出分级化发展态势,诸多网络路由的算法都是基于分级结构网络模式提出的。

Ad Hoc 无线网络作为一种新型的网络形式,相比于蜂窝式无线网络,其优势也较为明显。

首先,Ad Hoc 无线网络在任何时间、任何地点都不需要硬件基础网络设施的支持,而快速建立起一个移动通信网络,它的建立不依赖于其他介质,所以具有一定的独立性;其次,Ad Hoc 无线网络不存在有线基础设施的支持,主机之间的通信均通过无线传输来完成,因此,移动终端可得到的实际带宽要远小于最大带宽的理论值;最后,Ad Hoc 无线网络相对于蜂窝式无线网络要稳定的多。

2 对虫洞攻击和OLSR路由协议认知2.1 虫洞攻击的定义Ad Hoc 无线网络虫洞攻击的安全策略文/许桂月1 张常键2 宫海梅1虫洞攻击是网络中两个攻击节点共同作用,发起的一种攻击形式,在攻击节点之间存在一条高带宽、高质量的私有链条式通道,其专业术语称之为“隧道”。

虫洞攻击采取的方式特别简单,而且攻击速度相对较快,但是对Ad Hoc 无线网络的危害性却很大,采用常规的检测方法无法准确判定网络是否遭受虫洞攻击,因此,近年来,网络技术人员针对虫洞攻击的特点,制订了一套行之有效的安全防御措施,同时建立了相关的Ad Hoc 无线网络被攻击的预警机制,并收到了理想效果。

移动Ad Hoc网络主要安全漏洞分析与对策研究

移动Ad Hoc网络主要安全漏洞分析与对策研究
扰、 抗故障的能力 , 也使 其成 为在许多特殊场合进行 网络互联应
些基本要素 。上述移动通 信系统都需要有线 网络通信基础设施 的支持 , 如基站 、 交换机 、 卫星等 。这些设 施的建立 和运转需要
大量的人力和物力 , 成本 比较高 , 建设周期较长 。在某些特殊环 境或紧急情况下 , 如战场上部 队行 军的机动性 、 抗毁性 , 生洪 发
时它还将现有的主要网络中广泛应用 的中央控制管理 的功能进 行分布式处理 , 由网络各个节点同步完成 , 从而提 高了网络抗干
李 网 曾 琼 0
( 索贝数码科技股份有限公司技术研发部 四川 成都 60 4 ) 10 1
( 成都信息5 程学院计算机基础教学部 四川 成都 60 0 ) 1 2 1 13
摘
要
移动 A o dH c网络是 一种 移动 、 多跳、 自律 式无线网络 系统 , 有广 泛的应用场合 , 具 安全 问题一直是影 响其达到 完全 实用
Ke wor s y d Ad h c Vu n rbii Se urt o ntr a u e o l e a lt y c i c u e me s r s y
0 引 言
网络安全性主要包括 四个方 面的 内容 : 机密性 、 认证 性 、 完 整性校验 和不可否认性 。蜂 窝网络 、 集群 网络 、 无线局域 网络 、 卫星通信 网络等作为移动网络的主要形式其安全性也离不开这
Ab ta t s r c
Ab ta t bl d Ho e w r sa w rl s bl ewok s se fmoin. l — o ig a d a tn miain a d w t d sr cMo i A c n t o k i iee s mo i n t r y t m o t e e o mut h p n n u o o s t n i l i o I wie

移动Ad Hoc网络安全挑战及攻击研究(IJIEEB-V5-N3-6)

移动Ad Hoc网络安全挑战及攻击研究(IJIEEB-V5-N3-6)

I.J. Information Engineering and Electronic Business, 2013, 3, 49-58Published Online September 2013 in MECS (/)DOI: 10.5815/ijieeb.2013.03.06Security Challenges and Attacks in Mobile AdHoc NetworksCH.V. RaghavendranAssociate Professor, Ideal College of Arts & Sciences, Kakinada, Andhra Pradesh, IndiaE-mail: raghuchv@G. Naga SatishAssociate Professor, Ideal College of Arts & Sciences, Kakinada, Andhra Pradesh, IndiaE-mail: gantinagasatish@P. Suresh VarmaDr. , Professor, Adikavi Nannaya University, Rajahmundry, Andhra Pradesh, IndiaE-mail: vermaps@Abstract—Mobile Ad hoc Network (MANET) is an autonomous collection of mobile nodes that form a temporary network without of any existing network infrastructure or central access point. The popularity of these networks created security challenges as an important issue. The traditional routing protocols perform well with dynamically changing topology but are not designed to defense against security challenges. In this paper we discuss about current challenges in an ad hoc environment which includes the different types of potential attacks that are possible in the Mobile Ad hoc Networks that can harm its working and operation. We have done literature study and gathered information relating to various types of attacks. In our study, we have found that there is no general algorithm that suits well against the most commonly known attacks. But the complete security solution requires the prevention, detection and reaction mechanisms applied in MANET. To develop suitable security solutions for such environments, we must first understand how MANETs can be attacked. This paper provides a comprehensive study of attacks against mobile ad hoc networks. We present a detailed classification of the attacks against MANETs.Index Terms— MANETs, Security, Passive Attacks, Active Attacks, Network Layers.I.IntroductionSecurity is an ess ential s ervice for wired and wireless network communications. The success of MANET strongly depends on whether its security can be trusted. In this paper we focused on the routing security in MANET. Due to mobility and ad hoc nature, security in mobile ad hoc networks is particularly hard to achieve: the wireless links are usually fragile with high link broken ratio; nodes lack of enough physicalprotection can be easily captured, compromised, and hijacked; the sporadic nature of connectivity and the dynamically changed topology may cause frequent routes update; the absence of a certification authority and the lack of centralized monitoring or management point further deteriorate the situations. However, the characteristics of MANET pose both challenges and opportunities in achieving the security goals, such as confidentiality, authentication, integrity, availability, access control, and non-repudiation. There are a wide variety of attacks that target the weakness of MANET. During the last decade, extensive studies have been conducted on routing in mobile ad hoc networks, and have resulted in several mature routing protocols. However, in order to work properly, these protocol s need trusted working environments, which are not always available. In many situations, the environment may be adversarial. For example, some nodes may be selfish, malicious, or compromised by attackers. To address these issues, many schemes have been proposed to secure the routing protocols in ad hoc networks. So, in order to make MA NETs secure, all types of attacks are to be identified and solutions to be considered to make MANETs safe. Some of the attacks are considered in our study. However the list is possibly incomplete, and some more attacks on MANETs are likely to be discovered in near future. So Security issues in MANETs will remain a potential research area in near future.The rest of the paper is organized as follows. In Section 2 we introduced Mobile Ad Hoc Networks. In Section 3, we discussed on security requirements for MANETs. In Section 4, we described the security challenges. In Section 5, we briefly discuss about different type of attacks. In Section 6, security attacks are discussed on layer wise. In Section 7, we concluded our study on security challenges.II.Mobile Ad Hoc NetworksNow-a-days, Mobile ad hoc network (MANET) is one of the recent active fields and has received marvelous attention because of their self-configuration and self-maintenance capabilities [1]. MANET is a collection of mobile devices connected through wireless links to serve a specific purpose. MANETs provide users with easier ways to connect and communicate without the need for prior setup or a centralized server. MANETs are particularly used in situation where a fast installation is needed and no infrastructure is available. The only condition the device has to fulfill is the communication interface, as it needs one to build up a connection to other devices. The networks are self-organized and adaptive. As it has no infrastructure the participants are directly connected with one another and not to an access point, to a gateway or something similar. The nodes must, therefore, not just send and receive, but also forward packets. In MANETs the composition of the nodes varies very rapidly: in every moment a new node may connect or an established node may disconnect. MANETs use wireless connections for communication and that the devices are battery powered.MANETs are currently used in many areas and have various defining characteristics that differentiate them from other wireless networks such as WLAN. Possible applications of MANET include: soldiers relaying information for situational awareness on the battlefield, business associates sharing information during a meeting, attendees using laptop computers to participate in an interactive conference, and emergency disaster relief personnel coordinating efforts after a fire, hurricane or earthquake. Other possible applications include personal area and home networking, location-based services, and sensor networks.III.Security RequirementsAd hoc networks are very open to anyone. Their biggest advantage is also one of their biggest disadvantages. Anyone with the proper hardware and knowledge of the network topology and protocols can connect to the network. This allows potential attackers to infiltrate the network and carry out attacks on its participants with the purpose of stealing or altering information.Any routing protocol must encapsulate an essential set of security requirements like confidentiality, authentication, availability, integrity, non-repudiation, authorization and accounting [2]. These need to be addressed in order to maintain a reliable and secure ad-hoc network environment. These have to be protected against defects and more importantly against malicious intent.3.1 ConfidentialityConfidentiality is the process of keeping the information sent unreadable to unauthorized readers [2]. Transmission of sensitive information requires confidentiality. Routing and packet forwarding information must also remain confidential. Attacks against confidentiality aims at getting access to private or confidential data, for instance user names and passwords, credit card numbers, secret reports etc. To keep the confidentiality, it is required to ensure to communicate with right partner. Confidentiality can be achieved using any of the available encryption techniques, provided that proper access key systems are used. Protecting privacy involves more than encryption and requires more sophisticated techniques to hide the identity or the location of the user.3.2 AuthenticationAuthenticity means the verifying and proving the identity of the participants in a network. This is important to ensure genuine access to the network. The nodes wish to communicate with each other need to verity the identity of each other to satisfy that they are communicating with authorized party [2].3.3 AvailabilityServices or resources should be available to genuine users whenever required. It ensures the survivability of the network despite malicious incidents. This is very important in many applications.3.4 IntegrityThe integrity is the ability to guarantee that the received message is the real one that has not been tampered or changed. This is an essential in situations such as banking, military operations and equipment controls. As with confidentiality, integrity can apply to a stream of messages, a single message or selected fields within a message [2]. But, the most useful and straightforward approach is total stream protection. Integrity guarantees that the authorized parties are only allowed to modify the information or messages so that it is never corrupted.3.5 Non-repudiationThe goal of non-repudiation is related to a fact that if an entity sends a message, the entity cannot deny that the message was sent by it. If a message is sent, the receiver can prove that the message was sent by the alleged sender. In the same way, after sending a message, the sender can prove that the message was received by the alleged receiver. This may be of great importance in some situations but might not be in some others.3.6 Authorization and AccountingNodes participating in a network need to have proper permissions to access shared resources on that network. In a MANET, nodes should be able to restrict othersfrom accessing private information on their devices. Moreover, in some cases, the authorization policies are accompanied by accounting mechanisms to track resource utilization to identify bottlenecks, charging users for services or for statistical information about the network. Both authorization and accounting require robust methods to ensure correctness of protocols and proper utilization of resources.IV.Security ChallengesActive attacks [3, 4, 5] in MANET range from deleting messages, injecting messages, impersonate a node etc thus violating confidentiality, authentication, availability, integrity, and non-repudiation. Unlike the wired networks achieving security in MANETs is challenging. According [6] Ad hoc networks pose a number of nontrivial challenges to security design, such as the following.4.1 Dynamic TopologyNodes are mobile and can be connected dynamically in an arbitrary manner. Links of the network vary timely and are based on the proximity of one node to another node. This dynamis m could be better protected with distributed and adaptive security mechanis ms [2]. 4.2 ScalabilityScalability is an important issue concerning security. Security mechanisms should be capable of handling a large network as well as small ones [1].4.3 AutonomousNo centralized administration entity is available to manage the operation of the different mobile nodes.4.4 Poor Transmission QualityThis is an inherent problem of wireless communication caused by several error sources that result in degradation of the received signal.4.5 Bandwidth OptimizationWireless links have significantly lower bandwidth than the wired links.4.6 Device DiscoveryIdentifying relevant newly moved in nodes and informing about their existence need dynamic update to facilitate automatic optimal route selection.4.7 Infrastructure less and Self OperatedSelf healing feature demands MANET should realign itself to blanket any node moving out of its range.4.8 Limited ResourcesMobile nodes rely on battery power, which is a scarce resource. Also computational power and storage capacity are limited.4.9 Limited Physical SecurityMobility implies higher security risks such as peer-to-peer network architecture or a shared wireless medium accessible to both legitimate network users and malicious attackers.4.10 Ad hoc AddressingChallenges in standard addressing scheme are to be implemented.4.11 Topology MaintenanceUpdating information of dynamic links among nodes in MANETs is a major challenge.Providing secure communication in such changing and dynamic environment, as well as protection against specific threats and attacks, leads to development of various security schemes and architectures.V.Security AttacksMANET provides network connectivity between mobile nodes over potentially multihop wireless channels mainly through Link Layer protocols that ensure one-hop connectivity, and Network Layer protocols that extend the connectivity to multiple hops. These distributed protocols assume that all nodes are cooperative. This assumption is unfortunately not true in an unfriendly environment. Because cooperation is assumed but not enforced in MANETs, malicious attackers can easily disrupt network operations by violating protocol specifications.Many characteristics might be used to classify security attacks in the MANETs [7]. They would include looking at the behavior of the attacks (passive vs. active), the source of the attacks (external vs. internal), the processing capability of the attackers (mobile vs. wired), the number of the attackers (single vs. multiple) different protocol layer, stealthy or non-stealthy, and cryptography or non-cryptography related.5.1 Passive vs. ActiveThe Passive attacks steal valuable information in the targeted networks. Examples of passive attacks are eavesdropping attacks and traffic analysis attacks. Detecting this kind of attack is difficult because neither the system resources nor the critical network functions are physically affected to prove the intrusions [8].An Active attack attempts to alter system resources or affect their operation [8]. These actively alter the data, with the intent of overloading the network, obstructing the operation or to cut off certain nodesfrom their neighbors so they can not use the networks services effectively anymore. To execute active attacks, the attacker must be able to inject packets into the network. Table 1 shows the general taxonomy of security attacks against MANET. Examples of active attacks comprise actions such as message modifications, message replays, message fabrications and the denial of service attacks.Table 1: Security Attacks Classification5.2 External vs. InternalExternal attacks are launched by adversaries that are not legally part of the network. These attacks usually aim to cause network congestion, denying access to specific network function or to disrupt the whole network operations. Bogus packets injection, denial of service, and impersonation are some of the attacks that are usually initiated by the external attackers.Internal attacks are sourced from inside a particular network. A compromised node with access to all other nodes within its range poses a high threat to the functional efficiency of the whole network. Attacks that are caused by the misbehaving internal nodes are difficult to detect because to distinguish between normal network failures and misbehavior activities in the ad hoc networks is not an easy task.5.3 Mobile vs. Wired AttackersMobile attackers have the same capabilities as the other nodes in the ad hoc networks. Their capabilities to harm the networks operations are also limited because of limited resources. With the limited transmitting capabilities and battery powers, mobile attackers could only jam the wireless links within its vicinity but not the whole networks operations.Wired attackers are attackers that are capable of gaining access to the external resources such as the electricity. Since they have more resources, they could launch more severe attacks in the networks, such as jamming the whole networks or breaking expensive cryptography algorithms. Existence of the wired attackers in the ad hoc networks is always possible as long as the wired attackers are able to locate themselves in the communication range and have access to the wired infrastructures. 5.4 Single vs. Multiple AttackersAttackers might choose to launch attacks against the ad hoc networks independently or by colluding with the other attackers. Single attackers usually generate a moderate traffic load as long as they are not capable to reach any wired facilities. Since they also have similar abilities to the other nodes in the networks, their limited resources become the weak points to them [9]. If several attackers are colluding to launch attacks, defending the ad hoc networks against them will be much harder. Colluding attackers could easily shut down any single node in the network and be capable to degrading the effectiveness of network’s distributed operations including the security mechanis ms.5.5 Attacks on Different Layers of the Internet ModelThe attacks can be classified according to the five layers of the Internet model. Table 2 presents a classification of various security attacks on each layer of the Internet model. Some attacks can be launched at multiple layers.Table 2: Security Attacks on each layer in MANET5.6 Stealthy vs. Non-stealthy AttacksSome security attacks use stealth, where the attackers try to hide their actions from either an individual who is monitoring the system or an intrusion detection system (IDS). But other attacks such as DoS cannot be made stealthy.5.7 Cryptography vs. Non-cryptography Related AttacksSome attacks are non-cryptography related, and others are cryptographic primitive attacks. Table 3 shows cryptographic primitive attacks and the examples.Table 3: Cryptog raphic Primitive Attacksyer-Wise Security Attacks6.1 Physical Layer Attacks6.1.1 Eavesdropping:This is intercepting and reading of messages and conversations by unintentional receivers. The nodes share a wireless medium and the wireless communication use the RF spectrum and broadcast by nature which can be easily intercepted with receivers tuned to the proper frequency. Signals broadcast over airwaves can be easily intercepted with receivers tunedto the proper frequency. As a result transmitted message can be overheard as well as fake message canbe injected into the network.6.1.2 Interference and Jamming:Accidentally or intentionally, interference can happen with radio waves of MANETs, because WLAN use unlicensed radio frequencies. Other electromagnetic devices operating in the infrared or 2.4 GHz RF can overlap with WLA N traffic. A powerful transmitter can generate signal that will be strong enough to overwhelm the target signal and can disrupting communications. This condition is called jamming. Jamming attacks can be mounted from a location remote to the target networks. This makes this attack extremely inevitable. Pulse and random noise are the most common type of signal jamming [9].6.2 Data Link Layer Attacks6.2.1 Traffic Analysis:Traffic analysis attack adversaries monitor packet transmission to infer important information such as a source, destination, and source-destination pair. Dataon who is communicating with whom, how often, how much, and when is easily available to any eavesdropper within range of the wireless network. Even if the payload is encrypted, standard MANET protocols transmit enough header and routing information in the clear making traffic analysis relatively easy for attackers. Traffic analysis is a threat to secure communication, either by identifying targets for attacks such as denial-of-service or encryption cracking, or by revealing communication relationships. Traffic analysisin ad hoc networks may reveal:•the existence and location of nodes •the communications network topology•the roles played by nodes•the current sources and destination of communications and•the current location of specific individuals or functions6.2.2 Disruption MAC (802.11):Many attacks can be launched in link layer by disrupting the cooperation of the protocols of this layer. Wireless medium access control (MAC) protocols haveto coordinate the transmission of the nodes on the common communication or transmission medium. The IEEE 802.11 MA C is vulnerable to DoS attacks. To launch the DoS attack, the attacker may exploit the binary exponential backoff scheme. For example, the attacker may corrupt frames easily by adding some bitsor ignoring the ongoing transmission. Capture effect is an important effect to consider in link layer, which means that nodes that are heavily loaded tend to capture the channel by sending data continuously, thereby resulting lightly loaded neighbors to back off endlessly. Malicious nodes may take the advantage of this capture effect vulnerability. Another vulnerabilityto DoS attacks is exposed in IEEE 802.11 MAC through Network Allocation Vector (NA V) field carried in the RTS/CTS (Ready to Send/Clear to Send) frames.6.2.3 WEP weakness:The WEP was designed by a group of IEEE volunteer members, aiming at giving some layer of security to wireless networks. IEEE 802.11 W EP incorporates Wired Equivalent Privacy (W EP) to provide WLAN systems a modest level of privacy by encrypting radio signals. The WEP protection technique suggested for adhoc network fall short of the objective of data privacy, data integrity and authentication. Various security standards such as IEEE 802.11i, WPA, and IEEE 802.1 X were suggested to enhance the security issues in 802.11.Despite their efficiency, these standards do not provide any robustness to the security approach for monitoring of the authentication in a distributed architecture. Some of the weaknesses 802.11 WEP are listed below [11] [12] [13],•Key management is not specified in the W EP protocol.•The initialization vector (IV) used in WEP is sent in clear.•The WEP has not planed a mechanism to ensure data source authentication.The combined use of a non-cryptographic integrity algorithm, CRC 32 with the stream chipper is a security risk and may cause message privacy and message integrity attacks.6.3 Network Layer Attacks6.3.1 Wormhole Attack:The wormhole attack [14] is one of the most sophisticated and severe attacks in MANETs. The wormhole attack is possible even if the attacker has not compromised any hosts and even if all communication provides authenticity and confidentiality. In this attack, a pair of colluding attackers record packets at one location and replay them at another location using a private high speed network. The Fig 1 shows the Wormhole attack. It is also possible for the attacker to forward each bit over the wormhole directly, without waiting for an entire packet to be received before beginning to tunnel the bits of the packet, in order to minimize delay introduced by the wormhole. Furthermore, the attacker is invisible at higher layers; unlike a malicious node in a routing protocol, which can often easily be named, the presence of the wormhole and the two colluding attackers at either endpoint of the wormhole are not visible in the route.Fig. 1: Wormhole attack6.3.2 Blackhole Attack:In this attack, a malicious nodes trick all their neighboring nodes to attract all the routing packets to them. It exploits the routing protocol to advertise itself as having a good and valid path to a destination node. It tries to become an element of an active route. As in the wormhole attacks, malicious nodes could launch the black hole attacks by advertising themselves to the neighboring nodes as having the most optimal route to the requested destinations. The blackhole attack is illustrated in Fig 2. However, unlike in the wormhole attacks where multiple attackers colluded to attack one neighboring node, in the black hole attacks, only one attacker is involved and it threatens all its neighboring nodes.Fig. 2: Blackhole attackThe blackhole attack is performed in two steps. At first step, the malicious node exploits the mobile ad hoc routing protocol such as AODV, to advertise itself as having a valid route to a destination node, even though the route is spurious, with the intention of intercepting the packets. In second step, the attacker consumes the packets and never forwards. In an advanced form, the attacker suppresses or modifies packets originating from some nodes, while leaving the data from the other nodes unaffected.6.3.3 Byzantine attack:Byzantine attack can be launched by a single malicious node or a group of nodes that work in cooperation. A compromised intermediate node works alone or set of compromised intermediate nodes works in collusion to form attacks. The compromised nodes may create routing loops, forwarding packets in a long route instead of optimal one, even may drop packets. This attack degrades the routing performance and also disrupts the routing services [15].6.3.4 Flooding attack:In this attack, attacker exhausts the network resources, such as bandwidth and to consume a node’s resources, such as computational and battery power or to disrupt the routing operation to cause severe degradation in network performance. For example, in AODV protocol, a malicious node can send a large number of RREQs in a short period to a destination node that does not exist in the network. Because no one will reply to the RREQs, these RREQs will flood thewhole network. As a result, all of the node battery power, as well as network bandwidth will be consumed and could lead to denial-of-service [16].6.3.5 Resource consumption attack:In MANETs energy is a critical parameter because the battery-powered devices try to conserve energy by transmitting only when absolutely necessary [17]. The target of resource consumption attack is to send request of excessive route discovery or unnecessary packets to the victim node in order to consume the battery life. An attacker or compromised node thus can disrupt the normal functionalities of the MANET. This attack is also known as sleep deprivation attack.6.3.6 Location disclosure attacks:This attack is a part of the information disclosure attack. The malicious node leaks information regarding the location or the structure of the network and uses the information for further attack. It gathers the node location information such as a route map and knows which nodes are situated on the target route and then plans further attack scenarios. The leakage of such information is devastating in security sensitive scenarios Traffic analysis is one of the unsolved security attacks against MANETs.6.4 Trans port Layer Attacks6.4.1 Session hijacking:Session hijacking is a critical error and gives a malicious node the opportunity of behaving as a legitimate system. The attacker takes the advantage that, all the communications are authenticated only at the beginning of session setup and performs the session hijacking attack. At first, the attacker spoofs the IP address of target machine and determines the correct sequence number that is expected by the target and performs a DoS attack on the victim. As a result, the target system becomes unavailable for some time. The attacker now continues the session with the other system as a legitimate system.6.4.2 SYN flooding:The SYN flooding attack is also Denial of Service (DoS) attack which is performed by creating a large number of half-opened TCP connections with a victim node. For two nodes to communicate using TCP, they must first establish a TCP connection using a three-way handshake. The three messages exchanged during the handshake, illustrated in Figure 3. The sender sends a SYN mess age to the receiver with a randomly generated ISN (Initial Sequence Number). The receiver also generates another ISN and sends a SYN message including the ISN as an acknowledgement of the r e c e iv ed S YN me s s ag e.T he s en de r s e nds acknowledgement to the receiver. In this way the connection is established between two communicating parties using TCP three way handshakes.Fig. 3: TC P Three Way Handshake6.5 Application Layer Attacks6.5.1 Repudiation:Firewalls are used to keep packets in or keep packets out in the network layer. In the transport layer, entire connections can be encrypted, end-to-end. But these solutions taken to solve authentication or non-repudiation attacks in network layer or in transport layer are not enough to solve the problems. Repudiation refers to a denial of participation in the communication. Example of repudiation attack on a commercial system includes a selfish person could deny conducting an operation on a credit card purchase or deny any on-line transaction [10].6.6 Multilayer AttacksSome security attacks can be launched from multiple layers instead of a particular layer. Examples of multi-layer attacks are denial of service (DoS), man-in-the middle and impersonation attacks.6.6.1 Denial of Service:In Denial of service (DoS) type of attack, the attacker injects a large amount of junk packets into the network. These packets overspend a significant portion of network resources, and introduce wireless channel contention and network contention in the MANET. The limitation of the wireless links is utilized in resource depletion attacks. The attackers transfer big, unnecessary volumes of data between them to deplete the bandwidth of the links. The resource depletion attack is shown in the Figure 4. During this transfer A and B might send and receive only with a limited efficiency.Denial of service attacks aim at the complete disruption of the routing function and therefore the entire operation of the ad hoc network. Specific instances of denial of service attacks include the routing table overflow [18] and the sleep deprivation torture [19]. In a routing table overflow attack the malicious node floods the network with bogus route creation packets in order to consume the resources of the participating nodes and disrupt the establishment of legitimate routes. The sleep deprivation torture attack aims at the consumption of batteries of a specific nodeby constantly keeping it engaged in routing decisions.SYN w ith ISNaACK ISNa and SYN w ithACK ISNb。

无线移动Ad Hoc网络违规行为分析

无线移动Ad Hoc网络违规行为分析

无线移动Ad Hoc网络违规行为分析无线移动Ad Hoc网络违规行为分析摘要:无线移动Ad Hoc网络通过IEEE 802.11MAC协议中DCF机制竞争无线信道,该技术的特点是多个接入节点共享一个无线信道。

在分布式和开放的无线网络环境中,无线网络用户间需要有效和公平地使用有限的网络资源。

然而,有些节点为了自身利益,利用违规行为,获得大的网络优势。

本文主要分析MAC层存在的违规行为及产生这些违规行为的原因。

关键词:无线移动Ad hoc网络IEEE 802.11协议DCF机制违规行为1、引言近几年,随着社会的进步,人们对灵活、快捷、方便的通信方式要求越来越高,无线网络经历了一个快速开展阶段,提出了许多新的研究课题,无线移动自组网(Wireless Mobile Ad Hoc Networks)受到广泛关注,由于其不需要预先布置固定的根底设施,能充分表达无线网络的移动性和灵活性,因而非常适合战场通讯、灾难救助等场合。

无线移动Ad Hoc网络是一个复杂的由多个无线节点组成的分布式、动态自组织、多跳的通讯系统。

它的每个节点既是端节点,又是路由节点。

无线移动Ad Hoc网络的节点进行数据传输时,采用无线媒体访问控制(MAC)占用信道。

IEEE802.11MAC协议通常使用DCF机制,其核心是CSMA/CA〔带有回避冲突的载波侦听多址接入〕,该技术的共同特点是多个接入节点共享一个无线信道。

但是在不可信的网络环境中,一些有自私性行为的节点可能不遵循MAC协议而获得很大的信道带宽资源,本文主要分析MAC层存在的违规行为及产生这些违规行为的原因。

2、协议的介绍IEEE802.11的MAC层协议对于信道竞争的解决有两种方式:一种是集中式机制(PCF点协调功能),另一种是分布式机制(DCF分布协调功能)。

本文主要是针对DCF机制中存在的违规行为进行检测。

DCF机制是基于CSMA/CA〔带冲突防止的载波侦听多址接入〕协议。

移动Ad Hoc网络中一种匿名攻击及防御策略研究


移 动 A e网络 中一 种 匿名 攻 击及 防御 策 略研 究 dHo
Re e r h o nd o s a c n a Ki f Ano m o s Ata k a f n e ny u t c nd De e c S r t g e n M o ie Ad Ho t r t a e isi b l c Ne wo k
验证 表 明改 进 的策略 能在 移动环 境 中抵御 统计暴 露 攻 击这 种 匿名攻 击方式 , 强 了匿名性 。 增
种 被动 攻击方 式 , 它依 据概率 的观点 , 利用 统计 和
排 除 的方法 , 过计 算 出 与 目标 节点 通 信 的节 点 所 通
l 统计 暴 露攻 击 思想 和步 骤 r j ]
摘 要 : 用 概 率 模 型 检 测 工 具 P IM 证 实 统 计 暴 露 攻 击 能 够 破 坏 ANO R 协 议 的 匿名 性 。 此 改 进 A DR 应 RS D 为 NO 协 议 的 节 点 输 出方 式 , 出 全 局 同步 发 送 策 略 和 组 同 步 发 送 策 略 。概 率 模 型 检 测 表 明 , 同 步 发 送 策 略 适 应 提 组 移 动 AdHo e网 络 匿 名 通信 需 求 , 防 范 统 计 暴 露 攻 击 , 可 并能 提供 低 延 迟 , 节 点 移 动 影 响 小 的 匿 名 服 务 。 受 关 键 词 : 计 暴 露 攻 击 匿 名 通信 统
c m m u c to m m u e t o i t . o nia i n i n o m b l y i
Ke r s: t ts ia s l s r ta k, no ymo s o y wo d sa itc 1dico u e a t c a n u c mmunc ton,mo l Ho ne wo ks ia i bi Ad e c t r , p o a i si de h c n r b b l tc mo 1c e kig i

移动无线AdHoc网络中的路由安全问题

:+2*.+ 则 用 于 帮 助 路 由 协 议 绕
在 相 应 的 路 由 信 息 。因 此 为 了 减 少路由发现的时间, 该协议必须 配有大量的存储器。 目 前 , 在 !&#5% 提 出 的 路 由协议中均没有太多安全方面 的考虑,所以非常容易受到攻 击。
)’ !"#(% 中 的 路 由 安 全
安全通常是指对潜在攻击、 威胁、 入侵的检测识别并做出相 应 的 动 作 。 在 !&#5% 中 攻 击 通 常可分为消极攻击和主动攻击 两类。对于消极攻击而言, 攻击 者并不破坏路由协议的正常运 行, 而仅仅是通过窃听业务数据 来 发 现 可 以 攻 击 的 信 息 。这 种 攻 击 方 式 很 难 被 检 测 出 来 。对 于 主 动攻击而言, 攻击者通常试图修 改数据, 或者想通过获得权限向 网络中的数据流中插入虚假的 数 据 包 。主 动 攻 击 可 以 进 一 步 分 为 外 部 攻 击 和 内 部 攻 击 。内 部 攻 击指攻击者属于该网络的一部 分, 而外部攻击指攻击者不属于 该网络。 由于内部攻击的节点已经 属于该网络并拥有部分权限, 所 以它对网络的危害会更加严重, 下 面 为 !&#5% 中 的 一 些 主 动 攻 击的类型。 ・黑 洞 在该类型的攻击中,恶意的 节点想截获某个节点 & 的信息, 它便使用路由协议来广播自己 是 距 离 节 点 & 最 近 的 节 点 。从 而 恶意节点便可以截获其它节点 发向节点 & 的数据。 ・拒 绝 业 务
&’ !"#(% 中 的 路 由 协 议
在 !"#5% 中 存 在 着 多 种 路 由协议, 可以分为两类: 一类是
&94; , 当 4/E 进 行 路 由 发 现 时

移动Ad Hoc网络中针对拥塞的RoQ DDoS攻击及其防御

移动Ad Hoc网络中针对拥塞的RoQ DDoS攻击及其防御任伟;刘腾红;金海
【期刊名称】《计算机研究与发展》
【年(卷),期】2006(43)11
【摘要】根据网络容量理论,移动Ad Hoc网络中存在针对拥塞的RoQ分布式拒绝服务攻击,其攻击模式包括脉冲攻击、循环攻击、自消耗攻击和泛洪攻击.防御机制包括检测和响应,检测信号包括RTS/CTS包频率、信号干涉频率以及包重传次数,响应机制依靠ECN标记和通知.NS2模拟结果显示,复杂拓扑结构将更容易受到攻击,攻击节点的分散将加大攻击效果.脉冲攻击产生明显的吞吐率和延迟抖动,当同速率攻击流增加到5个时,受害流吞吐率下降到77.42%,延迟增加110倍.
【总页数】6页(P1927-1932)
【作者】任伟;刘腾红;金海
【作者单位】中南财经政法大学信息学院,武汉,430074;华中科技大学计算机科学与技术学院,武汉,430074;香港科技大学计算机系,香港;中南财经政法大学信息学院,武汉,430074;华中科技大学计算机科学与技术学院,武汉,430074
【正文语种】中文
【中图分类】TP3
【相关文献】
1.一种用于移动Ad Hoc网络的拥塞适应路由协议 [J], 蒋道霞;潘守伟;徐佳;刘凤玉
2.移动ad hoc网络中DOS攻击及其防御机制 [J], 易平;钟亦平;张世永
3.移动Ad Hoc网络的跨层优化拥塞控制 [J], 徐伟强;汪亚明;俞成海;刘良桂;张云华
4.802.11移动Ad Hoc网络中针对MAC层的分布式拒绝服务攻击 [J], 任伟;金海
5.移动Ad Hoc网络基于路由协议的拥塞控制 [J], 徐祎;周少琼;柏诗玉
因版权原因,仅展示原文概要,查看原文内容请购买。

防范典型网络攻击和受攻击方法分析

防范典型网络攻击和受攻击方法分析随着互联网发展的迅猛,网络安全问题越来越受到人们的关注。

在当今社会中,网络攻击不仅呈现出数量激增的趋势,而且攻击手段和手法也在不断升级。

为了保证网络系统的安全和稳定,防范网络攻击已经成为企业管理和个人安全的重要问题。

下面将就几种典型的网络攻击方式进行分析,并提供防范受攻击的方法。

一、Phishing AttackPhishing Attack(钓鱼攻击)是一种通过仿冒合法的网站或电子邮件取得受害者个人账户信息的攻击手段。

攻击者通常会利用社交工程学的技巧,以伪造的信任机构打扮成银行、电子商务网站、政府机构等负责人员发送电子邮件或者网站链接,诱骗受害者填写个人账户信息。

近年来,Phishing Attack攻击者的手段越来越高明,甚至使用了采用欺诈性短信或者内容欺骗的犯罪手法。

防御策略:1. 将符合自身业务范畴的所有网站、电子邮件都加入第三方反钓鱼机构的黑名单。

2. 用户网站维护的人员要进行培训、普及计算机安全常识。

3. 在网站页面的“帮助”中加入钓鱼警示信息。

二、DDoS AttackDDoS攻击是指分布式拒绝服务攻击(Distributed Denial of Service AttacK),是一种旨在使网络或者服务器资源耗尽以达到服务拒绝或使服务器停止运行的攻击手段。

防御策略:1. 加密数据和传输数据:可以借助VPN、SSL、TLS等工具对网络流量和通信进行加密和加密通信。

2. 设立服务器资源:设立目标,以限制对服务器的访问次数和访问数据包数量,防止服务器负载和资源消耗。

三、Worms and Viruses蠕虫病毒是一种独立于计算机操作系统的病毒,常常利用漏洞、互联网和本地网络来散布和传播。

恶意病毒程序可以轻易地在受害者计算机上繁殖自身,并根据预定的程序在计算机上执行。

防御策略:1. 安装流行的防病毒软件。

2. 更新软件包:当出现新的漏洞时,随时更新所有软件包,弥补漏洞。

  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。
相关文档
最新文档