FP7Реинтеграция2008–2011

SECURINET · Security management in multi-radio networks

7РП — „Хора“ (Действия „Мария Кюри“)

Период
2008-10-01 → 2011-03-31
Финансиране от ЕС
37 500 €
Участници
1
Схема
MC-ERG

Линиите свързват координатора с партньорите.

Накратко на български

Сигурността в мрежи с различни радиовръзки, като Wi-Fi и RFID, се изследва чрез създаване на разпределени центрове за откриване на хакерски атаки. Това помага за по-бързото разпознаване на необичайно поведение и защита на данните без зависимост от един единствен сървър.

Този кратък обзор е генериран от изкуствен интелект

Кратко обяснение, генерирано от езиков модел по текста на CORDIS. Оригиналът е по-долу.

Резултати накратко

Security management in multi-radio networks

The emergence of novel networking technologies ,e.g. Wi-Fi-enabled ad hoc networks, Radio frequency identification (RFID), 3G+, is driving the need for developing a solution that interconnects in a secure manner changing sets of clients and services. In order to ensure the desirable level of security, we aimed to provide a novel Multi-Radio enabled Distributed Security Operation Centre (MR-DSOC). This centre was intended to detect intrusions (e.g. intrusion targeting the routing protocol) in a distributed manner so as to prevent from a single point of failure and deal with the cooperative nature of nowadays networks. As first steps towards this goal, attacks reported in the literature were surveyed and categorised relying on a representation / formalism that captures the complexity and temporal dependencies between each of the constituting sub-tasks. Based on these modelled attacks, we have further derived appropriate distributed intrusion detection which parses events as close as close as possible from the device that generates it so as to diminish the number of long distant communications. Based on the above parsed events, intrusion detection takes place. This consists in analysing a sequence of events so as to identify a pattern that characterises an intrusion attempt. Such an intrusion system, qualified as a signature-based intrusion system, has been designed, developed and experimented in a Wi-Fi-enabled ad hoc network. In addition, this system is complemented with an anomaly detector that aims at finding patterns in the event which do not conform to the expected behaviour. For this purpose, Kohonen map, a powerful tool for automatically categorising a system activity, is used. In practice, the events provided by the monitored system are first pre-processed in order to train a Kohonen map which permits to define a region representing the normal behaviour of the observed subject. Based on the trained Kohonen map, any activity that does not scope with the defined normal behaviour is identified as an anomaly. Such a backend method does not necessitate amending the technical specification of the subject. Meanwhile, it also permits to detect undiscovered attacks (i.e. anomalies that deviate from a normal behaviour) that are not yet reported on the literature. A prototype of an anomaly detection system has been developed, experimented (focusing on a spoofing attack) and validated on a RFID system. Experiments show that the time and memory related to the training phase and the anomaly detection together is minimal. Overall, such a multi-radio enabled distributed security operation centre, integrating anomaly and intrusion detection as well as event aggregation capabilities, participates to getting less profitable for malicious intruders to gain unauthorised access to different personal or institution resources. From a sociological point of view, this project hence contributes in increasing the safety and the security by fighting against illegal intrusions.

Текст от CORDIS, на английски · Данни: CORDIS, © Европейски съюз

Цел на проекта

Spurred by the emergence of new networking technologies (Wifi, 3G,bluetooth, Wimax enabled technologies) and the advance of generalized eCommerce frameworks, interest has move towards the development of a global solution that interconnect in a secure manner changing set of mobile clients, services and networks. This construction of Internet-scale applications introduces a new set of challenges consisting in designing and implementing usable private/public secure systems deployed over planetary networks, including large-scale multi-radio networks. In order to ensure fundamental security properties (i.e., confidentiality, integrity and availability) of such a system, we propose a novel Multi-Radio enabled Distributed Security Operation Center (MR-DSOC) that targets applications deployed in multiple networks environment. The proposed system aims to improve the detection of misuses and minimizes the amount of damages caused by attacks. Special care will be put on providing a solution adapted to multi-radio networks; this topic remaining neglected by research community despite the certain socio-economic potential of multi-radio based applications and services. In order to deal with the limitations of multi-radio networks (heterogeneity, topology dynamicity, high churn rate), we propose a novel MR-DSOC which is optimally based on an event-based monitoring and communication component. This innovative approach renders our SOC more adaptable to network failure, less vulnerable to attacks due to its distributed nature, and capable of detecting any attack/intrusion which is coordinated and originated from dispersed sites.

Оригинален текст от CORDIS (на английски).

Участници

  • UNIVERSITE DE FRANCHE-COMTE · BesanconКоординаторФранция

Връзки

Данни: CORDIS, © Европейски съюз