MANET is seen as a promising technology that helps facilitate range extension in tactical edge networks (TENs) where both realtime broadcast and unicast are critical communications. These services are usually provided by proactive routing protocols with Multipoint Relay (MPR) technology. The standardized MPR selection method produces redundant MPR nodes which can cause repeated transmissions of broadcast traffic in TENs where bandwidth and power are scarce. Efficient minimum MPR set optimization remains a challenge. In addition to MPR selection, network connectivity is another important feature for how to best deploy connected MANETs at the tactical edge and ensure its reliable connectivity. To the best of our knowledge, little research has been done on this front. In this paper, we propose a holistic MPR selection (HMS) strategy that selects nearly-optimized MPR sets for a MANET in a pre-defined area at varying radio transmission ranges. We show through simulations that HMS is very close to the lower bound of the optimal MPR number and reduces over 50% MPRs compared to the greedy heuristic method in most tactical edge scenarios. We introduce a method to arrive at the minimum MPR size for fully covering a pre-defined area with different radio transmission ranges and investigate the relationship of MPR set with network connectivity. We developed the algorithm with simple geometry and found that our MPR comparison results among HMS, the minimum MPR size, and the lower bound of the optimal MPR number deliver radio range boundaries that differentiate three different grades of connectivity. The range boundaries can be used as an advanced feature for how to best deploy a MANET at the tactical edge for reliable connectivity.
Situational awareness (SA) information in tactical mobile ad hoc networks (MANETs) is essential to enable commanders to make informed decisions during military operations. Sharing SA information in MANETs is a challenging problem because missions are run with dynamic network topologies, using unreliable wireless links, and with devices that have strict bandwidth and energy constraints. Development and validation of efficient data delivery methods in MANETs often require simulation; however, the literature is sparse regarding simulations specifically for SA dissemination. In this paper we present a simulation implementation for a newly proposed Opportunistic SA Passing (OSAP) scheme and investigate its efficiency in realistic scenarios. Moreover, we propose several metrics aimed at facilitating evaluation of SA dissemination schemes in general, and we demonstrate the applicability of the metrics in our simulation results. Our simulation provides a flexible framework and evaluation platform for experimental studies of SA data dissemination in tactical MANETs.
The distinctive features of mobile ad hoc networks (MANETs), including dynamic topology and open wireless medium, may lead to MANETs suffering from many security vulnerabilities. In this paper, using recent advances in uncertain reasoning that originated from the artificial intelligence community, we propose a unified trust management scheme that enhances the security in MANETs. In the proposed trust management scheme, the trust model has two components: trust from direct observation and trust from indirect observation. With direct observation from an observer node, the trust value is derived using Bayesian inference, which is a type of uncertain reasoning when the full probability model can be defined. On the other hand, with indirect observation, which is also called secondhand information that is obtained from neighbor nodes of the observer node, the trust value is derived using the Dempster-Shafer theory (DST), which is another type of uncertain reasoning when the proposition of interest can be derived by an indirect method. By combining these two components in the trust model, we can obtain more accurate trust values of the observed nodes in MANETs. We then evaluate our scheme under the scenario of MANET routing. Extensive simulation results show the effectiveness of the proposed scheme. Specifically, throughput and packet delivery ratio (PDR) can be improved significantly with slightly increased average end-to-end delay and overhead of messages.
Mobile Ad hoc NETworks (MANETs) are a promising communication technology for tactical environments and emergency response operations. However, the features of MANETs, including dynamic topology and open wireless medium, lead to many security vulnerabilities. Malicious nodes can drop or modify packets that are received from other nodes and diminish the reliability of networks. Therefore, secure routing in MANETs is an important area of research. In this paper, we propose a scheme that enhances routing security based on trust. In the proposed scheme, in order to improve the accuracy of trust values with indirect observations, we use Dempster-Shafer theory of evidence to fuse observers' opinions. Consequently, a more accurate trust value can be calculated from indirect observations. We then utilize the trust value to enhance the MANET routing protocol security. Simulation results are presented to demonstrate the effectiveness of the proposed scheme.
In mobile ad hoc networks (MANETs), security is a challenging research topic due to the special characteristics of MANETs, such as no pre-defined infrastructure, unreliable link connections, and nomadic nature. Trust-based schemes are considered as effective mechanisms associated with cryptographic techniques for thwarting a variety of attacks, e.g., Packet drop attacks. Because of the properties of MANETs, trust establishment needs an intelligent approach to identify attackers' misbehavior. In this paper, we focus on mitigating threat from attackers who deliberately drop and modify packets. We propose a scheme of trust establishment based on Bayesian networks, which can effectively perform causal reasoning. Based on this model, other causes, e.g., Unreliable wireless connections, which also can result in packet dropping, will be distinguished from maliciousness and thus, a more accurate trust can be calculated. Simulation results demonstrate the performance and effectiveness of the proposed scheme in malicious environments.
Mobile tactical networks (MTNs) require agile operation, robustness, strong security protection, and high efficiency in order to fulfill their missions in contested environments. Research has shown that the classical layered protocol architecture has limitations and many cross-layer security techniques have been proposed in order to address these requirements. Most cross-layer techniques focus on a specific solution. A general framework is needed in order to support future diversified security applications. In this paper, we propose a cross-layer security management (CLSM) framework for MTNs, which provides a platform for developing various security services in MTNs. CLSM formalizes several functional blocks and control flows among these blocks, which include a local layer security-related attribute classification module, a security information retrieval engine, a security metric evaluation engine, a security knowledge repository, a shared security metric store, and a security related services module. We describe how CLSM can improve security performance in MTNs through two examples: intrusion detection and agile routing.
In this paper, we present the necessary methods and techniques for simulating a wide-band multi-hop side-channel between two distant peer nodes in a Mobile Ad hoc Network (MANET). Simulating such a side-channel is helpful in understanding its potential and experimenting with its cyber warfare benefits, and for discovering effective ways to detect it. Implementing a content-bearing side-channel in which the full frame payload is used for messaging requires the ability to access the full communication stack in the simulator. We have implemented a fully functional multi-hop side-channel on the EXata/Cyber (QualNet) simulation tool to a level of detail where it could potentially be used in-line with applications such as voice or video for real-time, real-life emulations. We provide the details of our implementation and evidence of the benefits of such a side-channel via test scenarios. Such simulations may be used to facilitate military personnel's understanding of the effects cyber tools may have on their operations, in particular, Adaptive Dispersed Operations where military units are mobile.
Current mobile agent algorithms for mapping faults in computer networks assume that the network is static. However, for large classes of highly dynamic networks (e.g., wireless mobile ad hoc networks, sensor networks, vehicular networks), the topology changes as a function of time. These networks, called delay-tolerant, challenged, opportunistic, etc., have never been investigated with regard to locating faults. We consider a subclass of these networks modeled on an urban subway system. We examine the problem of creating a map of such a subway. More precisely, we study the problem of a team of asynchronous computational entities (the mapping agents) determining the location of black holes in a highly dynamic graph, whose edges are defined by the asynchronous movements of mobile entities (the subway carriers). We determine necessary conditions for the problem to be solvable. We then present and analyze a solution protocol; we show that our algorithm solves the fault mapping problem in subway networks with the minimum number of agents possible, k=γ+1, where γ is the number of carrier stops at black holes. The number of carrier moves between stations required by the algorithm in the worst case is \(O(k \cdot n_{C}^{2}\cdot l_{R} + n_{C}\cdot l_{R}^{2})\), where n C is the number of subway trains, and l R is the length of the subway route with the most stops. We establish lower bounds showing that this bound is tight. Thus, our protocol is both agent-optimal and move-optimal.
Mobile ad hoc networks (MANETs) are notoriously difficult to defend against attack. In this paper we demonstrate that by optimizing a previously reported covert timing channel, it is possible to simultaneously improve the reliability of the channel and create a metric that reliably detects attacks. Using standard methods from information theory, we compute the capacity of the covert channel and show that it is reduced under wormhole attack. This result leads us to a novel application of error-correcting codes to our covert channel, where the number of errors corrected provides a measure of the likelihood that a route traverses a wormhole. This technique does not use any of the bearer-channel communications bandwidth nor does it require modifications to the protocols or hardware.
Cooperative communication is considered a promising technique to increase channel capacity and improve reliability in wireless and cellular networks. Although cooperative communication provides significant benefits, it also raises a number of serious security issues as malicious nodes may impersonate and affect the integrity of the communication. In this paper, we propose a prevention-based security technique for cooperative communication taking into consideration authentication protocol, based on hash chains and Merkle trees, along with physical layer parameters which relate to the channel state information. Based on this consideration, we derive the closed-form secured throughput equations for proactive relay selection in cooperative communication that provides both hop-by-hop and end-to-end authentication and integrity protection. The simulation results show that our proposed solution, which provides authentication and protects data integrity, has a higher throughput performance when compared to existing schemes that do not consider security.
In this thesis we look at mobile agent solutions to black hole search and related problems. Mobile agents are computational entities that are autonomous, mobile, and can interact with their environment and each other. The black hole search problem is for a team of these agents to work together to map or explore a graph-like network environment where some elements of the network are dangerous to the agents. Most research into black hole search has focussed on finding a single dangerous node: a black hole. We look at the problem of finding multiple black holes and, in the case of dangerous graph exploration, multiple black links as well.We look at the dangerous graph exploration problem in the network model. The network model is based on a normal static computer network modelled as a simple graph. We give an optimal solution to the dangerous graph exploration problem using agents that start scattered on nodes throughout the network. We then make the problem more difficult by allowing an adversary to delete links during the execution of the algorithm and provide a solution using scattered agents.In the last decade or two, types of networks have emerged, such as ad hoc wireless networks, that are by their nature dynamic. These networks change quickly over time and can make distributed computations difficult. We look at black hole search in one type of dynamic network described by the subway model, which we base on urban subway systems. The model allows us to look at the cost of opportunistic movement by requiring the agents to move using carriers that follow routes among the network's sites, some of which are black holes. We show that there are basic limitations on any solution to black hole search in the subway model and prove lower bounds on any solution's complexity. We then provide two optimal solutions that differ in the agents' starting locations and how they communicate with one another.Our results provide a small window into the cost of deterministic distributed computing in networks that have dynamic elements, but which are not fully random.
Black hole search (Bhs) is the problem of mapping or exploring a network where there are dangerous sites (black holes) that eliminate any incoming searcher without leaving a discernible trace. Dangerous graph exploration (Dge) extends the Bhs problem to include dangerous links (black links). In the literature, both problems have only been studied under the assumption that no faults occur in the network during the exploration. In this paper, we examine the impact that link failures can have on the exploration of dangerous graphs. We study the Dge problem under the following conditions: there are multiple black holes and black links, the network topology is unknown, the searchers are initially scattered in arbitrary locations, and the system is totally asynchronous. In this difficult setting, we assume that links can fail during the computation. We present an algorithm that solves the Dge in the presence of such dynamic link failures. Our solution to the problem works with an optimum number of searchers in a polynomial number of moves. This is the first result dealing with fault-tolerant computations in dangerous graphs.
Replay attacks and their associated risks in mobile tactical networks are analyzed and a cooperative joint detection scheme is evaluated. The scheme adopts a combination of duplicated frame detection and link likelihood verification to defend against both local and remote replays. A formal analytical framework is established employing realistic tactical radio models and network scenarios. The results obtained illustrate the network-wide risk of the attack and the effectiveness of the detection scheme.
We study the complexity of the popular one player combinatorial game known as Flood-It. In this game the player is given an n × n board of tiles where each tile is allocated one of c colours. The goal is to make the colours of all tiles equal via the shortest possible sequence of flooding operations. In the standard version, a flooding operation consists of the player choosing a colour k, which then changes the colour of all the tiles in the monochromatic region connected to the top left tile to k. After this operation has been performed, neighbouring regions which are already of the chosen colour k will then also become connected, thereby extending the monochromatic region of the board. We show that finding the minimum number of flooding operations is NP-hard for c ≥ 3 and that this even holds when the player can perform flooding operations from any position on the board. However, we show that this " free " variant is in P for c = 2. We also prove that for an unbounded number of colours, Flood-It remains NP-hard for boards of height at least 3, but is in P for boards of height 2. Next we show how a c − 1 approximation and a randomised 2c/3 approximation algorithm can be derived, and that no polynomial time constant factor, independent of c, approximation algorithm exists unless P=NP. We then investigate how many moves are required for the " most demanding " n × n boards (those requiring the most moves) and show that the number grows as fast as Θ(√ cn). Finally, we consider boards where the colours of the tiles are chosen at random and show that for c ≥ 2, the number of moves required to flood the whole board is Ω(n) with high probability. Abstract: We consider a class of highly dynamic networks modelled on an urban subway system. We examine the problem of creating a map of such a subway in less than ideal conditions, where the local residents are not enthusiastic about the process and there is a limited ability to communicate amongst the mappers. More precisely, we study the problem of a team of asynchronous computational entities (the mapping agents) determining the location of black holes in a highly dynamic graph, whose edges are defined by the asynchronous movements of mobile entities (the subway carriers). We present and …
Finding a good cup of coffee in Paris is difficult even among its world-renowned cafés, at least according to author David Downie (2011). We propose a solution that would allow tourists to create a map of the Paris Métro system from scratch that shows the locations of the cafés with the good coffee, while addressing the problem of the tourists losing interest in the process once they have found good coffee. We map the problem to the black hole search problem in the subway model introduced by Flocchini et al. at Fun with Algorithms 2010. We provide a solution that allows the tourists to start anywhere and at any time, communicate using whiteboards on the subway trains, rely on much less information than is normally available to subway passengers, and work independently but collectively to map the subway network. Our solution is the first to deal with scattered agents searching for black holes in a dynamic network and is optimal both in terms of the team size and the number of carrier moves required to complete the map.
....... ................................................................................................................................. i Résumé ........ ................................................................................................................................... i Executive summary ........................................................................................................................ iii Sommaire ....................................................................................................................................... iv Table of contents ............................................................................................................................. v List of figures ................................................................................................................................. vi
Mobile Ad Hoc Networks (MANETs) have been seen as a key tactical communication technology. However, one of the most severe attacks in MANETs, the wormhole attack remains a sizable challenge. Most existing wormhole detection techniques rely on specialized hardware such as directional antennas, GPS, or high precision clocks, which can limit their efficacy. In order to provide an efficient and accurate detection mechanism for wormhole attacks, we present a new method based on signal processing techniques, in which purposely shaped traffic is transmitted, analysed at the destination node by constructing the reception time data into a “signal”, and then transforming this signal to the frequency domain using the Fast Fourier Transform (FFT). Using this technique, the wormhole attack can be quickly and accurately identified. We demonstrate in simulation and in a testbed that the proposed methodology can be used to detect an attack within seconds. In addition, the detection mechanism proposed is agnostic of routing protocol and does not require any specialized hardware support.
Traditional authentication techniques for wireless communications are facing great challenges, due to the open radio propagation environment and limited options of transmission techniques. A new continuous physical layer authentication technique with time-varying transmission parameters is investigated to enhance the security of orthogonal frequency division multiplexing (OFDM) system. A preceded cyclic prefix (PCP) sequence, which introduces an additional signaling link to carry the time-varying transmission parameters, is employed in each OFDM symbol for physical layer authentication. The new PCP sequences are generated with the same time and frequency domain characteristics as data-carrying OFDM signals to reduce the interception probability. With the proper recovery of system parameters and interference cancellation, only legitimate users can successfully decode the PCP sequence and obtain necessary parameters to decode OFDM data. In addition, a cross layer design approach, which addresses the dependency among PCP configurations, authentication performance and transmitting performance, is introduced to continuously generate optimal PCPs according to dynamic communication conditions. Numerical simulations confirmed that the system performance, in terms of system robustness, security and stealth, can be significantly improved by using the proposed continuous authentication.
We report on the challenges faced in the implementation and simulation of a side-channel communication based on frames with an intentionally corrupted Frame Check Sequence (FCS). Systematically corrupted FCSs can be used to enable covert communications between nodes that share the same algorithm for deciphering the FCS. In order to assess the possibility in detecting this side-channel communication it is necessary to have the ability to simulate it as well as to implement it on actual devices. Nearly all simulators drop corrupted frames before they reach their destination, making it impossible to simulate any side-channel communication based on intentionally corrupted FCS. We present an example of the modifications required to prevent this as applied to a well-known simulator called Sinalgo. We also discuss problems encountered when trying to intentionally corrupt the FCS on actual devices.
In cognitive radio mobile ad hoc networks (CR-MANETs), secondary users can cooperatively sense the spectrum to detect the presence of primary users. In this chapter, we propose a fully distributed and scalable cooperative spectrum sensing scheme based on recent advances in consensus algorithms. In the proposed scheme, the secondary users can maintain coordination based on only local information exchange without a centralized common receiver. We use the consensus of secondary users to make the final decision. The proposed scheme is essentially based on recent advances in consensus algorithms that have taken inspiration from complex natural phenomena including flocking of birds, schooling of fish, swarming of ants, and honeybees. Unlike the existing cooperative spectrum sensing schemes, there is no need for a centralized receiver in the proposed schemes, which make them suitable in distributed CR-MANETs. Simulation results show that the proposed consensus schemes can have significant lower missing detection probabilities and false alarm probabilities in CR-MANETs. It is also demonstrated that the proposed scheme not only has proven sensitivity in detecting the primary user's presence but also has robustness in choosing a desirable decision threshold.
Thomas Kunz合作论文数Department of Systems and Computer Engineering, Carleton University1
K. El-Khatib合作论文数Faculty of Business and Information Technology, University of Ontario Institute of Technology1