Abstract

Mobile ad-hoc networks (MANETs) have great potential applications in military missions or emergency rescue due to their no-infrastructure, self-organizing and multi hop capability characteristics. Obviously, it is important to implement a low-cost and efficient mechanism of anti-invasion, anti-eavesdropping and anti-attack in MANETs, especially for military scenarios. The purpose of intruding or attacking a MANET is usually different from that of wired Internet networks whose security mechanism has been widely explored and implemented. For MANETs, moving target defense (MTD) is a suitable mechanism to enhance the network security, whose basic idea is to continuously and randomly change the system parameters or configuration to create inaccessibility for intruders and attackers. In this paper, a two-layer IP hopping-based MTD approach is proposed, in which device IP addresses or virtual IP addresses change or hop according to the network security status and requirements. The proposed MTD scheme based on the two-layer IP hopping has two major advantages in terms of network security. First, the device IP address of each device is not exposed to the wireless physical channel at all. Second, the two-layer IP hops with individual interval and rules to obtain enhanced security of MANET while maintaining relatively low computational load and communication cost for network control and synchronization. The proposed MTD scheme is implemented in our developed MANET terminals, providing three level of network security: anti-intrusion in normal environment, intrusion detection in offensive environment and anti-eavesdropping in a hostile environment by combining the data encryption technology.

Highlights

  • Mobile ad-hoc networks (MANETs) are playing an increasingly important role in many environments and applications, for example, in emergency environments where fixed network infrastructure might be damaged

  • MANETs used in military applications might face a hostile environment, which means that the network might be intruded and eavesdropped

  • In order to evaluate our solution, we simulated a military battle in Section 4.1 and built a MANET environment based on the Android platform

Read more

Summary

Introduction

Mobile ad-hoc networks (MANETs) are playing an increasingly important role in many environments and applications, for example, in emergency environments where fixed network infrastructure might be damaged. The IP hopping of MTD is a typical MTD mechanism, which prevents attackers from eavesdropping and intrusion by dynamically changing IP addresses [3]. The use of IP hopping technology can prevent illegal users from intruding into the network to identify the commander, for example, and prevent them from grabbing the operational intention and situation by analyzing the network and communication procedure. To enhance the network security of our developed MANET communication terminals [4,5] in its upgrade version, a two-layer IP hopping-based MTD approach is designed and implemented on an Android platform. Combined with the technology of data encryption, the implemented MANET system has three level of network security: anti-intrusion in normal environment, intrusion detection in offensive environment and anti-eavesdropping in a hostile environment. The tests concerning effectiveness and the performance evaluation are presented in Section 4 and conclusions are outlined in the final section

Related Work
Two-Layer IP Hopping Approach
Access Randomization Scheme
Virtual IP Hopping Randomization Analyses
Tests and Performance Evaluation
Prototype Implementation Based on Android
A Comparison of Intrusion Prevention Scheme
Findings
Conclusions
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call