Evaluation of Performance Parameters Based Intrusion Detection System
Anjali Patel, Navdeep Saluja · International Journal of Engineering, Management & Medical Research (IJEMMR) · 2015
Mobile ad-hoc network is a wireless network having mobiles nodes communicating with each other using radio frequencies. They are known to be infrastructure less network because they perform transmission and reception without using any additional intermediate devices or towers. Such network supports dynamic topologies due to their movable nature of nodes participating in communication. Hence they suffer from instant change in behavior of nodes and which is complicated to track their activities. Sometimes the nodes change their primary functionality and starts affecting the normal operations of data, controlling and starts dropping of packets. Such nodes are known as malicious attacker and needs to be detected soon before majorly destroying the transmission. The process of finding out these nodes is known as intrusion detection system (IDS).They applies network monitoring to detect the unwanted access or packet drops which was intentionally applied by these malicious nodes. In the last few years there are so many approaches are developed to reduce the impact of these attacks. Also there detection is not accurately performed in defined time boundaries. Existing approaches may also mislead the detection by considering the inappropriate parameters and hence the actual nodes operation might get suffered from this. Thus there must be some mechanism which performs early detection along with accurate analysis and reduced false reports. This work presents a novel performance based intrusion detection system (PB-IDS) for getting its goal in an efficient manner. Some of the parameters considered here to identify the performance drops or dynamic change in nodes behavior are mobility, routing overhead, collision, packet drop ratio and throughput. The system takes the base values of these parameters as normal and then continuously monitors the nodes on these parameters. If the nodes shows change in behavior there are some more monitoring factors added into it to confirm whether the node is malicious or not. One the malicious nodes is detected then its transmission is immediately stopped and the other nodes are informed using an alarming mechanism. The approach uses AODV protocol for proving the concept as a simulated prototype developed in network simulator 2. It also reduces the false detection rates and timely founds the ambiguous collisions. Experimental evaluation shows the proposed approaches outperforms the existing mechanism of IDS such as EACK, Watchdog and Pathrater. Also it is observed that the malicious behavior detection ratio is high and the false detection is very low with optimal overhead.