AT TOPPaper 944 US-M-EDOWN
Integrating Intrusion Detection and Fault Localization in MANETS
Tsang,SimonTelcordia
Sterne,DanSparta
Sethi,AdarshpalUniversity of Delaware
Natu,MaitreyaUniversity of Delaware
Mouchtaris,PetrosTelcordia
Balenson,DaveSparta
In this exploratory paper, we propose that intrusion detection and fault localization techniques in MANET environments (which are commonly separate systems) should work cooperatively. We argue that an integrated approach will exhibit improved accuracy, and also minimize system overheads and redundancy. Using detection of in-band wormhole attacks as an illustrative example, we outline how an integrated approach can better distinguish malicious network attacks from “normal” network delays and outages.

Daniel F. Sterne is a Branch Chief at SPARTA’s Security Research Division. Over a period of 17 years with Trusted Information Systems, McAfee Research, and now SPARTA, Mr. Sterne has led and made key contributions to a broad range of computer and network security research and consulting projects. He currently leads or co-leads projects on intrusion detection and worm defense for mobile ad hoc networks (MANETs) funded by the Army Research Laboratory, Army CERDEC, and DARPA. He was a principal investigator and co-founder of the DHS- and NSF-funded DETER network security testbed, a collaborative project with several major universities, and leader of its DDoS Defense Working Group. Mr. Sterne led the DARPA-funded Active Network Intrusion Detection and Response (AN-IDR) project, for which he received an Excellence in Industrial Research award. Previously, he was a primary contributor to the Cooperative Intrusion Traceback and Response Architecture (CITRA) and the Intruder Detection and Isolation Protocol (IDIP) developed jointly with Boeing Phantom Works and University of California, Davis. His earlier accomplishments include leading the development of Domain and Type enforcement (DTE) and Object-Oriented DTE, which are programmable access control technologies for Unix kernels, firewalls, and CORBA applications. Mr. Sterne has published papers on security policy, trusted operating systems, assurance paradigms, firewalls, object-oriented security, MANET security, and intrusion detection and response. He was a major contributor to “An Introduction to Computer Security: The NIST Handbook”.