
Wireless communications have made today’s busy world even busier. The use of hand held devices such as iPads, tablets, notebooks etc. is increasing exponentially. The wireless nature of these devices makes them flexible and opportune. However, wireless devices encounter numerous security problems compared to their wired counterpart. The lack of physical connectivity (anchor-attachment) from the wireless device to the wired network makes the wireless devices more vulnerable and hard to protect against security threats. In this view we have proposed EAP-CRA protocol to counter the security threats during the security association between a wireless device and the wired network. Our protocol leverages the advantages of Public Key Infrastructure to provide a secure connectivity to the network in a multi agent environment. As with many security protocols, in the early stages, formal verification plays a vital role, particularly when the process of implementing the protocol is time consuming. We have used Symbolic Analysis Laboratory tools to formally verify the functionality of the EAP-CRA protocol. In this paper we present a number of Linear Temporal Logic formulas that we have established to prove the integrity of our proposal. By examining all possible execution traces of the proposed protocol we have proved that our protocol is complete and consistent.
In a Poisson Point Process (PPP) network model, in which the locations of Base Stations (BSs) are randomly distributed according to a Spatial Poisson Process, has been recently used as a tractable stochastic model to analyse the performance of downlink Heterogeneous Cellular Networks (HCNs). The HCN is modelled as a multi-tier cellular network where each tier is characterised by the transmission power level, propagation path loss exponent and density of BSs. The current works on HCN enabling Intercell Interference Coordination (ICIC) technique usually deal with Strict Frequency Reuse (FR) or Soft FR with a reuse factor of $\Delta=1$ in a Rayleigh fading channel. It has been assumed that all Base Stations (BSs) transmit continuously which leads to a reduction on the impact of number of users and RBs on network performance. In this paper, the performance of Soft FR with a reuse factor of $\Delta>1$ in Rayleigh-Lognormal fading channel is evaluated. The impact of the number of users and Resource Blocks (RBs) on Intercell Interference (ICI) are presented for Round Robin scheduling and indicator functions. The results show that there are opposite trends between coverage probability of Cell-Center User (CCU) and Cell-Edge User (CEU).
Wireless sensor networks (WSNs) have been used to monitor, control and automate different applications on local scale. Early research therefore, focused on designing MAC, network and transport layer protocols dedicated to meet the specifications of these local WSN applications. However, the idea of integrating sensor networks with the Internet to make the local sensor data accessible on a global scale has gained popularity in recent years. Integrating IP (Internet Protocol) and WSNs pose many challenges due to the different characteristics of these heterogeneous networks. Two integration architectures, proxy-based and network-overlay based have emerged in parallel. This paper surveys the protocols implementing these two integration architectures, their limitations and the extent to which they achieve seamless interoperability of IP and wireless sensor networks. We classify the reviewed protocols at transport and network layers and compare them in terms of relevant performance matrices. Our study shows that there are many limitations in the existing techniques and protocols and the idea of achieving seamless integration is only in its initial stages
Due to non-ideal conditions in the measurements of the wireless channel, high initial bit error rate (BER) in the preliminary key is resulted, which reduces the final secret key generation rate and even causes the secret key generation process fail. Aiming to resolve this problem, we first present and verify an optimal information reconciliation protocol; the validation experiment shows that not only the BER comes down more quickly, but also a higher information rate is achieved. Then, to address the problem of very high initial BER and further improve the efficiency of the secret key generation, we introduce the idea of pre-distillation into the secret key generation system, and present a pre-distillation method, which makes the initial BER comes down quickly, and ensures the subsequent information reconciliation be easily performed; hence the total key generation rate is improved. Experimental results demonstrate that the pre-distillation method has excellent ability of reducing the initial BER, especially in the case of very high initial BER. The combination of our proposed pre-distillation and our optimal information reconciliation is the most efficient one when the initial BER is larger than 0.15, and the information rate is improved by more than forty-nine times when the initial BER is 0.3
Modern Internet has enabled wider usage, resulting in increased network traffic. Due to the high volume of data packets in networking, sampling techniques are widely used in flow-based network management software to manage traffic load. However, sampling processes reduce the likelihood of anomaly detection. Many studies have been carried out at improving the accuracy of anomaly detection. However, only a few studies have considered it with sampled flow traffic. In our study, we investigate the use of an artificial neural network (ANN)-based classifier to improve the accuracy of flow-based anomaly detection in sampled traffic. A feedback from the ANN-based anomaly detector determines the type of the flow sampling method that should be used. Our proposed technique handles malicious flows and benign flows with different sampling methods. To evaluate the proposed sampling technique, a number of flow-based datasets are generated. Our experiments confirm that the proposed technique improves the percentage of the sampled malicious flows by about 7% and it can preserve the majority of traffic information
The main focus on the algorithmic theory is the network optimization. The goal of network optimization is to connect vertices of the network in an inexpensive manner. In this work we present an efficient algorithm to achieve the effective optimization for an undirected large scale graph. This work is a connectivity data structure that focuses on us to know the connectivity parameters of the existing networks and proposing algorithms to make is efficient to access the information on the network. The network is made efficient by considering the network as a graph with edge weight and edge capacity. The network thus formed makes use of the dynamic programming approach and then the routing optimization is achieved using the Hierarchical edge capacity routing algorithm (HECR). By using HECR algorithm, routing is achieved at two different levels of nodes. The proposed algorithm also addressed the load balancing in the network. It is fast for large number of nodes with 3% of less time and the route found converges to optimal
The dynamic of changing network topology and vehicle density in VANET are causing the dynamic of message traffic intensity. This situation requires adaptability of channel management to provide the channel capacity dynamically and proportionally. The length of CCH interval in VANET represents the capacity of channel or service rate of vehicles. The fixed pattern of CCH/SCH interval as published by IEEE 802.11p/1609.4 would become the constraint of adaptability of vehicles in VANETs. Moreover it would affect to VANET performance inefficient. This research proposes an adaptive scheme of CCH/SCH interval which proportional with density of vehicles based on the number of vehicle connected each other’s. To show how effective the proposed adaptive scheme of CCH/SCH interval can afford to improve of VANET performance (compared to fixed interval scheme of current IEEE standard), we analyze by combining mobility model and queuing network model. We assume that statistically there is a steady state of VANET topology which can be analyzed by using queuing network model. We specified the real map of highway in Bandung city along 10 Km length to achieve the representative experimental result. The various specified of speeds are: 70-90 Km/h, 90-110 Km/h, and 110-130Km/h, while the various of density of vehicle are 15, 30, 45, 60, 75, and 90 vehicles along 10Km length of highway. All of experiments performed in two main scenarios, i.e. the fixed CCH/SCH interval, and adaptive CCH/SCH interval which compared each other to see the improvement. The analytical result examined by simulation method. The experimental results show the improvement of adaptive CCH/SCH interval. The improvement of average delay is 10ms, and the improvement of system throughput is 450 kbps.
This paper presents an in-depth analysis on the effect of the coexistence in the 2.4 GHz band between IEEE 802.15.4 and IEEE 802.11 on the medium access control. We focus on the slotted CSMA/CA medium access algorithm that is used by IEEE 802.15.4 and analyse the delay that frames undergo when suffering from interference from a WiFi activity. We measure the overhead caused by the additional delay spent in the MAC sublayer frame queue before accessing the medium due to the presence of WiFi interference. We experimented different scenarios with overlapping channels and non-overlapping channels. We show that the two wireless protocols can coexist if we take into considerations the relative positions of the nodes to avoid very high interference and if we avoid monopolizing the channel with a very high rate WiFi traffic even under overlapping channels.
Multi-constrained Quality of Service (QoS) routing algorithm is always a difficult problem in routing research area, which is a NP problem. Software Defined Network (SDN) is a new network architecture, in which there’s few research on QoS routing. This paper generates the whole network virtual topology according to the characteristics of SDN, and based on the principle of simulated annealing, proposes a nonlinear annealing algorithm, which adapts to the SDN. Firstly we simplify the network topology by Dijkstra-like algorithm, and then introduce the nonlinear energy function, and then iterate the initial solution according to the simulated temperature, until find a feasible path from the source node to the destination node which satisfies the condition. Experimental results show that this algorithm has a higher success rate, better expansibility of network size, and better transplantation for the SDN than traditional QoS routing algorithm
RFID is a key technology that can be used to create the pervasive society. The tag is an important part of the RFID system and most popular tags are some low-cost passive tags. These tags have limited computing and storing resources, and no more attentions are paid to their security and privacy. So the application of these tags is not secure. Lightweight authentication protocols are considered as an effective method to solve the security and privacy of low-cost RFID tags. We propose a novel lightweight authentication protocol by means of some functions provided by EPCglobal Class-1 Gen-2 tags. The protocol enhances the difficulty to reveal the tag’s secrecy by using the tag’s partial identifier to generate the session messages between the tag and the reader. The tag’s partial identifier is generated randomly for each authentication. Otherwise, the tag’s identifier is randomly divided into two separate parts so as to avoid colliding from the 16-bit cyclic redundancy coding function. Some random numbers, which are generated by the tag and the reader respectively, randomize the session messages between the tag and the reader so as to resist against tracing attack and replay attack. Our proposed protocol can assure forward security and it can resist against de-synchronized attack. This protocol only uses some lightweight functions and it is very suitable to low-cost RFID tags
Existing mobile agent-enabled anomaly detection schemes have not considered temporal behavior for their correct functioning and detection of temporal anomalies. This study employs a holistic system approach to design an Enhanced mobile Agent-enabled Anomaly Detection System (EAADS) by designing two new algorithms. The proposed algorithms are not only important for the completeness of the EAADS, but also for the detection of the anomalies caused by the delayed arrival of the in situ verification results. The formal specifications of the individual algorithmic functionalities are addressed by employing the Petri net theory. A bottom-up synthesis of the individual Petri net modules is carried out to formulate a unified model, which has helped in the identification and removal of inconsistencies in the system design. This process formally characterizes the behavioral properties and the overall workflow of the EAADS. The standard unified Petri net model is then extended into a corresponding high class Generalized Stochastic Petri Net (GSPN) model to formalize and analyze the temporal behavior of the EAADS in a highly nondeterministic communication environment. Finally, the GSPNbased temporal behavior is validated through implementation of the functional specifications on a real testbed composed of the resource constrained MICAz motes. The theoretical and experimental results demonstrate the ability of the EAADS to detect certain types of anomalies and the aptness of the temporal behavior of the EAADS for the low resource sensor networks even in a highly nondeterministic communication environment
Software Defined Networking (SDN) has gained significant attention from network researchers and industry in recent years. Indeed, the SDN concept provides many advantages such as programmability and easy management of the network. However, it generates new challenges as scalability and performances issues, understanding in-depth the performances and limitations of the SDN concept is a prerequisite to its implementation and deployment in real networks. In this paper, we aim to present in a comprehensive way, the most important works that focus on performances of SDN. As SDN separates the control plane from the data plane, we first present research efforts made to enhance the performances of data plane devices, then, we give an overview of different solutions proposed to improve controller performances. We provide also an overview on recent control plane architectures with multiple controllers that have been proposed to meet performances and scalability constraints. Finally, we present the different techniques and tools used in literature to evaluate the performances of software defined networks
Internet has great impact on various facets of everyone’s life. With the enormous advantage Internet provides to users all around the world, it has some inherent weaknesses because of the protocol stack on which it is built. It can be easily attacked by attackers who exploit the vulnerabilities in the protocols and compromise systems and remotely control them to do further damage. Major attacks are focused on confidentiality, integrity and availability of data or resources. Flooding attack is one such resource availability attack which is a great cause of concern. Hackers can use the flooding attacks and cause Distributed Denial of Service (DDoS) attack with ease. With the increase and variations in the attack mode makes the investigation of these attacks essential. Random-UDP flooding attack is a different type of attack in which the attacker sends multiple UDP datagrams of different sizes at a time. This causes denial of service to the system and its resources. In this paper, we have proposed a technique for the forensics of Random-UDP flooding attack. We have tried to get as close as possible to the source of such attacks. The proposed technique is capable to identify the source of Random-UDP flooding bot attack.
One of the major challenges to realize the Internet of Things is to support IP mobility for the large amount of connected entities when they move between different locations and access methods. Current solutions for mobility are host centric, requiring support from the infrastructure, or breaks backwards compatibility, which will take a long time or high economic motivation to implement. Solutions for context information exchange are created for specific, small, or localized scenarios with centralized coordination that do not scale well. There is therefore a need for a solution which both scales well, and support IP mobility, without additional demands on current or future Internet infrastructure.We propose the use of a dual-overlay network structure for both information dissemination and as an alternative to current IP mobility technologies. It separates identities from location by introducing a second overlay network where the identity-to-location association is stored. We show analytically that the proposed solution provide logarithmic latency for localization and reduces the overall workload when the number of sensors per host increases beyond seven, with a workload reduction of 15 percentage points at fifteen sensors per host.
Energy efficiency is a major issue in Cloud computing infrastructure. The large power consumption is mainly attributed to the large number of modern data centers operating within. Developing these data centers includes dynamically expanding their infrastructures to meet the ever-increasing demand for huge computation, large storage, and massive communication. Energy conservation through optimization of resources and management policies in the Cloud are a viable solution. Using virtualization to save power and employing such practices as using Virtual Machines (VMs), Server Consolidation, and VM Live Migration. This paper investigates the opportunities for Green Cloud Computing (GCC) to obtain a more comprehensive prospect towards achieving energy efficient Cloud Computing, and presents an energy efficient network resources management approach in an Infrastructure as a Service (IaaS) Cloud model. We focus on developing an energy efficient algorithm by proposing a practical multi-level Cloud Resource-Network Management (CRNM) algorithm, which is implemented in a virtual Cloud environment using Snooze framework as the Cloud energy efficiency manager. The optimization focuses on the utilization of network bandwidth as main resource under test, while also taking into account the other resources, such as CPU and memory, to get the desired performance. We choose a fat tree topology as a common three tier architecture for Cloud data canters. We conclude that our proposed algorithm will save up to 75% of power consumption in Cloud data centers, with an observed increase in efficiency compared to Non-Power Aware (NPA), Power aware(PA), and Greedy algorithms, where network elements consume about 30% of the total power of Cloud data centers.
Recently, image steganography has received a lot of attention as it enables for secure multimedia communication.Payload capacity and stego image imperceptibility are a critical factors of any steganographic technique.In order to receive maximum embedding capacity with a minimum degradation of stego images, secret data should be embedded carefully in a specific regions.In this paper, data hiding is considered as an optimization problem related to achieving optimum embedding level of the cover image.Embedding data in edge area provide high imperceptibility.However, the embedding capacity of edge region is very limited.The work attempt to improve the edge based steganography by incorporates edge detection and vision science research.Genetic Algorithm that uses human visual system characteristics approach for data hiding is presented.Primarily, the approach applies Differences of Gaussian detector which closely resembles the human visual behavior.Secondly, the edge profusion indicates the level of threshold visibility with the help of Genetic Algorithm training.The suggested solution uses Contrast Sensitivity Function (CSF) which produces the edges based on the size of the embedding information.The authors of this paper compared their technique with other classical and recent works.The quality of the steganography is measured based on various quality metrics such as PSNR, wPSNR, SSIM and UIQI.These metrics declare the stability between imperceptibility and large embedding capacity.
Scale-free networks are a type of complex networks in which the degree distribution of the nodes is according to the power-law. Centrality of the nodes is a quantitative measure of the importance of the nodes according to the topological structure of the network. The commonly used centrality measures are the degree-based degree centrality and eigenvector centrality and the shortest path-based closeness centrality and betweenness centrality. We use the widely studied Barabasi-Albert (BA) model to simulate the evolution of scale-free networks. The model works by adding new nodes to the network, one at a time, with the new node connected to m of the currently existing nodes. Accordingly, nodes that have been in the network for a longer time have greater chances of acquiring more links and hence a larger degree centrality. While the degree centrality of the nodes has been observed to show a concave down pattern of increase with time; but the time-dependent variation of the other centrality measures has not been analyzed until now. In this paper, we study the time-dependent variation of degree centrality, eigenvector centrality, closeness centrality and betweenness centrality of the nodes during the evolution of a scale-free network according to the BA model
Aiming to cope up with relentless wireless traffic and improving link quality against high wall penetration loss, Third Generation Partnership Project proposed the heterogeneous deployment of low power indoor hot spots such as Femtocell Access Points (FAPs) over the existing cellular network topology. In this two-tier heterogeneous network (HetNet) where femtocells coexist with macrocell, the FAPs may spatially reuse the spectrum assigned to macrocell base station in an unplanned way and the mitigation of the generated co-channel interference becomes a major challenge. The problem is more severe with FAPs operating in a closed access mode, particularly in urban and sub-urban environment. In this work, the impact of interference in downlink on quality of service to macro user and femto user is analyzed by modeling the Signal-to-Interference and Noise Ratio and achieved user throughput. Simulation results show significant reduction of achieved user throughput and creation of coverage holes because of interference. It is clear that the performance of restricted access FAPs under co-channel operation need to be explicitly accounted for and optimized against both cross-tier and co-tier interference
Denial of Service (DoS) or Distributed Denial of Service (DDoS) is a powerful attack which prevents the system from providing services to its legitimate users. Several approaches exist to filter network-level attacks, but application-level attacks are harder to detect at the firewall. Filtering at application level can be computationally expensive and difficult to scale, while still creating bogus positives that block legitimate users. In this paper, authors show application layer DoS attack for SIP server using some open source DoS attack tools and also suggest a mechanism that can protect a given SIP server from application-level DoS attacks especially the attacks targeting the resources including CPU, sockets, memory of the victim server. In this paper author’s attempt to illustrate application layer distributed denial of Service (DDoS) attack on SIP Server such as SIP flooding attack, real time transport (RTP) flooding attack using open source DDoS attack tools. We propose a new DDoS defence mechanism that protects SIP servers from application-level DDoS attacks based on the two methodologies: IPtables and fail2ban detection. The attack flow detection mechanism detects attach flows based on the symptom or stress at the server, since it is getting more difficult to identify bad flows only based on the incoming traffic patterns. A popular software known as Wireshark which is a network protocol analyzer is used to capture the packets during DoS attack from the victim server Ethernet interface to detect the attacking host IP address and analysis the types of attack. We evaluate the performance of the proposed scheme via experiment