Detection and Prevention Techniques for Gray Hole Attack in MANET: Review
Amit A. Bhusari, P. M. Jawandhiya · 2013
(Mobile Adhoc network) is a infrastructure less network used for wireless communication. MANET can be built with the mobile nodes which can move anywhere at any time. This results into the dynamic topology of MANET. Each node is responsible for routing the message from one node to the other like a router, causes network more vulnerable to the different attacks. In this paper we will discuss about the gray hole attack type of DOS [2] attack, detection and prevention technique which disrupt the various network parameter as throughput, PDR and degrades the performance of the network. INDEX: Gray hole attack, DOS attack INTRODUCTION: MANET is a collection of mobile nodes that communicates with adjacent nodes without fixed infrastructure. It is decentralized network where the nodes act as a router to exchange the messages to other. A node can joins and leaves the network rapidly and it makes the topology dynamic. The dynamic topology [1] causes the security issues for MANET. Gray hole is a packet drop attack in which malicious node misbehaves the source node to forward the packets to destination and drops the packets coming from the source node or any intermediate nodes. Gray hole is widely used on AODV (Adhoc on demand distance vector) routing protocol. Gray hole Attack: Gray Hole attack is the attack on the adhoc network. In Gray Hole Attack [1] a malicious node refuses to forward certain packets and simply drops them. The attacker selectively drops the packets originating from a single IP address or a range of IP addresses and forwards the remaining packets. Gray Hole nodes in MANETs are very effective. Every node maintain a routing table that stores the next hop node information for a route a packet to destination node ,When a source node want to route a packet to the destination node , it uses a specific route if such a route is available in it’s routing table. Otherwise, nodes initiates a route discovery process by broadcasting Route Request (RREQ) message to it’s neighbors. On receiving RREQ message, the intermediate nodes update their routing tables for a reverse route to source node. A Route Reply (RREP) message is sent back to the source node when the RREQ query reaches either the destination node itself or any other node that has a current route to destination. Every node maintains a routing table that stores the next hop node information which is a route packet to destination node. If a source node is in need to route a packet to the destination node it uses a specific route and it will be checked in the routing table whether it is available or not. If a node initiates a route discovery process by broadcasting Route Request (RREQ) message to its neighbor, by receiving the route request message the intermediate nodes will update their routing tables for reverse route to the source. A route reply message is sent back to the source node when the RREQ query reaches either to the destination node or to any other node which has a current route to destination. Fig.1 Gray hole attack The gray hole attack has two phases: Phase 1: A malicious node exploits the AODV (Adhoc on demand distance vector) routing protocol to advertise itself as having a valid route to destination node, with the intention of interrupting packets of spurious route. Phase 2: In this phase, the nodes has been dropped the interrupted packets with a certain probability and the detection of gray hole attack is a difficult process. Normally in the gray hole attacks the attacker behaves maliciously for the time until the packets are dropped and then switch to their normal behavior. Both normal node and attacker are same. Due to this behavior it is very hard to find out in the network to figure out such kind of attack.