论文部分内容阅读
提出了无线传感器网络(WSN)中一种防御攻击的分布式入侵检测系统,包括以数据采集、处理和传输为目的的3层分层的体系结构和基于异常的分布式入侵检测算法.本地入侵检测系统(IDS)依附于WSN的每一个节点,其作用是采集网络运行的原始数据,以及计算本地异常指数,以此衡量当前节点的运行与正常运行情况之间的差别.在簇头和管理节点两个层次中进行异常指数的融合,分别形成簇级和网络级的异常指数.对融合算法进行了数学描述和理论推导,通过仿真并借助接受者操作特性(ROC)曲线,对节点、簇头和管理节点的运行情况进行了性能评估,总体结果证实了体系结构和算法的有效性.研究表明,这种融合算法能大幅提高系统的检测概率.
A distributed intrusion detection system based on defensive attack in Wireless Sensor Network (WSN) is proposed, which includes a three-layer hierarchical architecture for data acquisition, processing and transmission and an anomaly-based distributed intrusion detection algorithm. The detection system (IDS) is attached to each node of WSN, and its role is to collect the original data of network operation, as well as to calculate the local anomaly index to measure the difference between the current node operation and normal operation.In cluster head and management The two indexes of the nodes are clustered together to form the anomaly index at the cluster level and the network level respectively.Mathematical description and theoretical derivation of the fusion algorithm are carried out. By means of simulation and receiver operating characteristic (ROC) curve, Head and management node performance evaluation, the overall results confirmed the validity of the architecture and algorithms.Research shows that this fusion algorithm can greatly improve the detection probability of the system.