년 - 년
Mobile Ad-hoc Network 상에서 분산된 서비스에 대한 확신 값을 고려한 확장된 신뢰도 평가 기법 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제2호 2010.06 pp.51-57
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문은 이동 애드혹 네트워크 내에서 발생하는 기본적인 트랜잭션 메시지에 의미를 부여하고 추가적인 트랜잭션 메시지를 정의하며 확신성 요소를 추가하여 보다 나은 서비스를 제공하는 노드 선택의 기준이 될 수 있는 확장된 신뢰도 평가 기법을 제안하고, 이를 시뮬레이션하여 제안한 신뢰 도 평가 기법의 효용성을 보인다.
This paper proposes extended trust evaluation mechanism which is able to become the standard of the node selection which provides a better service by using the basic transaction message which occurs from within the mobile Ad-hoc network and the additional transaction message and add confidence value. Furthermore, throughout the simulation shows the efficiency of the proposed trust evaluation mechanism.
Mobile Ad-hoc Network 상의 분산된 서비스에 대한 신뢰도 평가 기법 설계 및 구현
한국융합보안학회 융합보안논문지 제9권 제4호 2009.12 pp.29-34
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이동 애드혹 네트워크 환경에서 신뢰할 수 없는 서비스들로 인해 과도한 트랜잭션이 발생되 고 있다. 본 논문은 이러한 문제점을 극복하기 위한 방안으로, 이동 애드혹 네트워크 내에서 발 생하는 기본적인 트랜잭션 메시지와 추가적인 트랜잭션 메시지에 의미를 부여하여 보다 나은 서비스를 제공하는 노드 선택의 기준이 될 수 있는 신뢰도 평가 기법을 제안한다. 제안한 신뢰 도 기법을 구현하고 시뮬레이션을 통해서 평가된 신뢰도 값을 확인한다.
The many transaction occurs because of service will not be able to trust in mobile Ad-hoc Network. Overcomes like this problem point with the plan for, This paper proposes the trust evaluation mechanism which is the possibility becoming the standard of the node selection which provides a better service by using the transaction message which is basic occurs from within the mobile Ad-hoc network and in the transaction message which is additional. At last, this paper embodies the trust mechanism which proposes, confirms the trust value which is evaluated with NS2 simulator.
네트워크 중심전을 위한 모바일 애드-혹 네트워크에서 노드의 이동성 예측 라우팅 기법
한국융합보안학회 융합보안논문지 제9권 제3호 2009.09 pp.53-60
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
네트워크 중심전을 위한 무선 애드-혹(Ad-hoc) 네트워크는 기존의 유선 네트워크와는 다르게 고정된 기지국이 존재하지 않고 무선 노드들만으로 구성된다. 무선 애드-혹 네트워크 내에서는 노드 자체의 에너지 제약과 잦은 이동으로 인해 네트워크 단절이 빈번하게 발생하게 된다. 그러므로 무선 애드-혹 네트워크 분야에서는 노드의 이동성에 따른 토폴로지 변경에 유연하게 반응하면서 전송 경로의 신뢰성을 향상시키는 기법이 반드시 요구된다. 본 논문에서는 AOMDV 라우팅 프로 토콜을 이용하여 경로 탐색 시에 응답하는 노드의 이동성을 고려하여 경로를 선택하는 기법을 제안한다. 제안한 기법을 적용함으로써 전송 경로의 신뢰성을 향상시켜 경로가 단절되어 재탐색 하는 횟수를 줄일 수 있다.
Mobile Ad-hoc Network for Network Centric Warfare(NCW), which is different from existent wired network, consists of mobile nodes without immobile base station. In mobile ad-hoc network, network cutting has occurred frequently in node because of energy restriction and frequent transfer of node. Therefore, it requires research for certain techniques that react softly in topology alteration in order to improve reliability of transmission path. This paper proposes path selection techniques to consider mobility of node that respond when search path using AOMDV routing protocol. As applying proposed techniques, We can improve reliability and reduce re-searching number of times caused by path cutting.
신뢰 모델을 이용한 보안 라우팅 기법에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제17권 제4호 2017.10 pp.11-16
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이동 노드로만 구성된 MANET은 응급 상황에서 신속하게 네트워크를 구축할 수 있는 장점 때문에 다양한 환경에적용되고 있다. 그러나 노드들의 이동으로 인한 동적 토폴로지와 링크 실패는 많은 라우팅 취약점을 노출하고 있으며, 네트워크 성능을 크게 떨어뜨릴 수 있는 요인이 된다. 본 논문에서는 신뢰 모델을 기반으로 한 안전한 라우팅 프로토콜기법을 제안하였다. 제안한 기법에서는 노드들에 대한 효율적인 신뢰 평가 및 관리를 위해 영역 기반 네트워크 구조를이용하였다. 노드들의 신뢰 평가는 노드들의 제어 패킷과 데이터 패킷의 폐기 비율 측정을 통해 이루어졌으며, 라우팅의 효율을 높이기 위하여 트래픽 검사를 실시하고 과도한 트래픽을 발생시키는 경로에 존재하는 노드들에 대한 DSN 검사하여 비정상행위 노드를 탐지하였다. 제안한 기법을 통해 경로상에 공격이 존재하더라도 안전하게 데이터 전송이이루어짐을 실험을 통하여 확인하였다.
MANET composed of only mobile node is applied to various environments because of its advantage which can construct network quickly in emergency situation. However, many routing vulnerabilities are exposed due to the dynamic topology and link failures by the movement of nodes. It can significantly degrade network performance. In this paper, we propose a secure routing protocol based on trust model. The domain-based network structure is used for efficient trust evaluation and management of nodes in the proposed technique. The reliability evaluation of nodes was performed by the discard ratio of control packet and data packet of the nodes. The abnormal nodes are detected by performing traffic check and inspecting of nodes on a path that generates excessive traffic in order to increase the efficiency of routing. It is confirmed through experiments of the proposed technique that data transmission is performed securely even if an attack exists on the path.
협업 기법을 이용한 침입탐지 탐지 방법에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제21권 제1호 2021.03 pp.121-127
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
무선 노드 외에 어떠한 인프라도 존재하지 않는 MANET은 빠른 네트워크 구성할 수 있는 장점을 가지고 있다. 하지 만 노드들의 이동, 무선 매체 등은 MANET이 가지고 있는 보안 취약점의 원인이기도 하다. 특히 네트워크상에 존재하 는 공격 노드들에 의한 그 피해는 다른 네트워크에 비해 상당히 크다. 따라서 공격노드들에 대한 탐지 기법과 공격으로 인한 피해를 줄이는 기법도 반드시 필요하다. 본 논문에서는 침입탐지의 효율성을 높이기 위한 계층구조 기법과 공격으 로 인한 피해를 줄이기 위해 P2P 메시 네트워크 구성 기법을 적용한 협업 기반 침입탐지 기법을 제안하였다. 제안한 기 법에서는 클러스터내 노드들에 대한 신뢰도 평가를 통해 사전에 공격 노드에 대한 네트워크 참여를 배제하였다. 그리고 공격 노드에 의한 공격이 탐지되면 클러스터 헤드간의 P2P 메시 네트워크를 통해 네트워크 전역에 공격 노드 정보를 빠르게 전달함으로써 공격 노드의 피해를 최소화하는 방법을 적용하였다. 제안한 기법의 성능 평가를 위해 ns-2 시뮬레 이터를 이용하였으며, 비교 실험을 통해 제안한 기법의 우수한 성능을 확인할 수 있었다.
MANET, which does not have any infrastructure other than wireless nodes, has the advantage of being able to construct a fast network. However, the movement of nodes and wireless media are also the causes of security vulnerabilities of MANET. In particular, the damage caused by the attacking nodes existing on the network is considerably greater than that of other networks. Therefore, it is necessary to detection technique for attacking nodes and techniques to reduce damage caused by attacks. In this paper, we proposed a hierarchical structure technique to increase the efficiency of intrusion detection and collaboration-based intrusion detection technique applying a P2P mesh network configuration technique to reduce damage caused by attacks. There was excluded the network participation of the attacking node in advance through the reliability evaluation of the nodes in the cluster. In addition, when an attack by an attacking node is detected, this paper was applied a method of minimizing the damage of the attacking node by transmitting quickly the attack node information to the global network through the P2P mesh network between cluster heads. The ns-2 simulator was used to evaluate the performance of the proposed technique, and the excellent performance of the proposed technique was confirmed through comparative experiments.
MANET에서 영역-키 기반 보안 라우팅 기법에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제5호 2020.12 pp.33-39
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이동 노드로만 구성된 MANET은 모든 노드들이 라우터 역할을 수행한다. 하지만 노드들의 빈번한 이동으로 인한 동적인 토폴로지는 라우팅 성능을 떨어뜨리고 많은 보안 취약점의 원인이기도 하다. 따라서 MANET의 성능을 좌우할 수 있는 라우 팅 기법에는 보안이 반드시 적용되어야 한다. 본 논문에서는 영역-키 기반 보안 라우팅 기법 적용을 통해 다양한 라우팅 공격 에 효율적으로 대응하고, 안전한 데이터 전송을 위한 기법을 제안하였다. 제안한 기법에서는 영역 기반 네트워크 구조를 이용 하였으며, 각 영역내 멤버 노드들을 관리하는 관리 노드를 이용하였다. 또한 각 노드들에 키를 발급하여 이를 이용한 라우팅 기법을 적용함으로써 공격 노드로 부터의 피해를 최소화하였다. 영역 관리 노드는 라우팅 정보를 암호화하기 위한 키 발급과 발급 정보를 관리한다. 데이터 전송을 원하는 멤버 노드는 영역 관리 노드로부터 발급받은 키를 이용하여 라우팅 정보를 암호 화한 후, 이를 이용하여 경로 발견을 수행하게 된다. 제안한 기법의 향상된 성능은 CBSR, ARNA 기법과 비교 실험을 통하여 확인하였으며, 실험을 통해 우수한 성능을 확인할 수 있었다.
In MANET consisting of only mobile nodes, all nodes serve as routes. However, the dynamic topology due to frequent movement of nodes degrades routing performance and is also cause of many security vulnerabilities. Therefore, security m ust be applied to routing techniques that can influence the performance of MANET. In this paper, we propose a technique for efficiently responding to various routing attacks and safe data transmission through application of zone-key based secu rity routing techniques. A zone-based network structure was used, and a management node that manages member nodes i n each zone was used in the proposed technique. In addition, the damage from the attacking node was minimized by issui ng a key to each node and applying this to a routing technique. The zone management node issues a key for encryption r outing information and manages the issuance information. A member node that wants to transmit data encrypts routing in formation using a key issued from the zone management node, and then performs path discovery using this. The improve d performance of the proposed technique was confirmed through a comparative experiment with the CBSR and ARNA tec hnique, excellent performance was confirmed through experiments.
무선 네트워크 환경에서 영역기반 침입탐지 기법에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제19권 제5호 2019.12 pp.19-24
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 이동 노드로만 구성되어 있기 때문에 기존의 유선 환경에서의 라우팅 프로토콜을 그대로 적용할 수 없 다. 따라서 이러한 특성이 고려된 라우팅 프로토콜이 필요하다. 특히 라우팅 단계에서 악의적인 노드들을 배제하지 못 한다면 네트워크 성능은 크게 떨어질 수 밖에 없다. 본 논문에서는 라우팅 성능을 향상시키기 위해 영역기반 침입탐지 기법을 제안하였다. 제안한 기법에서는 전체 네트워크를 일정한 영역으로 분할한 후 영역관리 노드를 이용하여 영역내 공격 탐지가 이루어지도록 하였으며, 멤버 노드로부터 수신한 완료 메시지를 이용하여 서로간 협업을 통해 경로상에 존 재하는 공격 노드를 탐지할 수 있는 방법을 제안하였다. 그리고 탐지한 공격노드 정보를 블록체인에 저장하여 공유함으 로써 네트워크에 참여하는 모든 노드들이 공격노드 정보를 공유할 수 있도록 하는 방법을 적용하였다. 제안한 기법의 성능 평가는 기존의 보안 라우팅 기법들과 비교 실험하였으며, 실험을 통해 제안한 기법의 우수한 성능을 확인할 수 있었다.
It is impossible to apply the routing protocol in the wired environment because MANET consists of only mobile nodes. Therefore, routing protocols considered these characteristics are required. In particular, if malicious nodes are not excluded in the routing phase, network performance will be greatly reduced. In this paper, we propose intrusion detection technique based on region to improve routing performance. In the proposed technique, the whole network i s divided into certain areas, and then attack detection within the area using area management node is performed. It is a proposed method that can detect attack nodes in the path through cooperation with each other by using comple tion message received from member nodes. It also applied a method that all nodes participating in the network can share the attack node information by storing the detected attack node and sharing. The performance evaluation of t he proposed technique was compared with the existing security routing techniques through the experiments and the superior performance of the proposed technique was confirmed.
MANET 환경에서 데이터 무결성 보장을 위한 블록체인 적용에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제18권 제5호 2018.12 pp.53-58
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 어떠한 인프라스트럭처의 도움 없이 이동 노드들로 구성되어 hop-by-hop 방식으로 데이터가 전달되는 구조가 블록체인과 매우 유사하다. 하지만 MANET은 이러한 특징 때문에 악의적인 노드에 의한 데이터 변조 또는 폐 기 등 다양한 위협에 노출되어 있다. 이러한 이유로 전송 데이터에 대한 무결성 보장은 MANET의 중요한 보요 요소이 다. 본 논문에서는 네트워크를 구성하는 노드들에 대한 신뢰도 값을 악의적인 노드들로부터 보호하기 위하여 블록체인 기술을 적용하는 방법을 제안하였다. 이를 위하여 클러스터 형태의 계층 구조를 이용하였으며, 클러스터 헤드만이 노드 들의 신뢰도 정보를 블록에 저장하고 이를 전파할 수 있도록 하였다. 또한 잘못된 블록의 전파를 차단하기 위하여 클러 스터 헤드 선출에 참여하는 노드들의 수와 클러스터 헤드의 신뢰도를 이용한 블록생성 난이도 자동 설정 기법을 적용 하였다. 이렇게 되면 악의적인 노드에 의한 블록 생성 및 전파를 차단할 수 있게 된다. 제안한 기법의 우수한 성능은 SAODV 기법과 비교 실험을 통해 확인할 수 있었다.
MANET transmits data by hop-by-hop method because it is composed of mobile nodes without support of any i nfrastructure. Its structure is very similar to a block chain. However, it is exposed to various threats such as data tampering or destruction by malicious nodes because of transmission method. So, ensuring the integrity of transmitt ed data is an important complement to MANET. In this paper, we propose a method to apply the block chain techni que in order to protect the reliability value of the nodes consisting the network from malicious nodes. For this, hiera rchical structure of a cluster type is used. Only cluster head stores the reliability information of the nodes in a bloc k and then, this can be spread. In addition, we applied block generation difficulty automatic setting technique using the number of nodes selecting cluster head and the reliability of cluster head to prevent the spread of wrong blocks. This can prevent block generation and spread by malicious nodes. The superior performance of the proposed techniq ue can be verified by comparing experiments with the SAODV technique.
위치정보 기반 가상 그룹을 활용한 효율적인 멀티캐스트 기법 연구 KCI 등재
한국융합보안학회 융합보안논문지 제17권 제5호 2017.12 pp.87-92
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 이동 노드들이 무선으로 연결되어 스스로 구성되는 네트워크로서 그룹 통신을 위한 분야에도 다양하게 적용되어 왔다. 하지만 노드들의 이동으로 인한 동적인 토폴로지는 그룹 통신에 참여하는 노드들에 대한 위치 정보 유 지가 어려워 라우팅 실패가 빈번히 발생하고 있다. 그리고 멤버 노드들에 대한 정보를 관리하기 위한 높은 오버헤드로 인해 네트워크 성능이 떨어지는 문제점을 가지고 있다. 본 논문에서는 멤버 노드들의 관리가 유연하고 신뢰성이 높은 위치기반 2-tier 가상그룹을 이용한 멀티캐스트 기법을 제안하였다. 제안한 기법에서는 네트워크를 셀룰러 존으로 구성 하여 노드들의 위치정보를 이용한 가상그룹을 구성하였다. 가상그룹내 멤버 노드들에 대한 위치정보 관리의 오버헤드 를 최소화하기 위하여 가상그룹 관리 노드를 선정하였다. 가상그룹 관리 노드는 멤버 노드들의 관리와 멀티캐스트 데이 터 전송시 신뢰성을 높이기 위하여 멤버 노드들의 패킷 전송률을 측정한 후 전송률이 낮은 게이트웨이 노드를 경로 설 정시 배제하도록 하였다. 제안한 기법의 우수한 성능은 AMRoute 기법, PAST-DM 기법과 비교 실험을 통해 확인할 수 있었다.
MANET is a network composed itself because mobile nodes are connected wirelessly. It has been applied to vari ous fields for group communication. However, the dynamic topology by the movement of the nodes causes routing f ailure frequently because it is difficult to maintain the position information of the nodes participating in the group co mmunication. Also, it has a problem that network performance is decreased due to high overhead for managing info rmation of member nodes. In this paper, we propose a multicast technique using location-based 2-tier virtual group that is flexible and reliable in management of member nodes. The network is composed of cellular zones and the vir tual group is constructed using the location information of the nodes in the proposed technique. The virtual group management node is selected to minimize the overhead of location information management for member nodes in th e virtual group. In order to improve the reliability for management of member nodes and multicast data transmissio n, it excludes the gateway node with low transfer rate when setting the route after the packet transmission rate of the member nodes is measured. The excellent performance of the proposed technique can be confirmed through com parative experiments with AMroute method and PAST-DM method.
[NRF 연계] 한국통신학회 ICT Express Vol.1 No.2 2015.09 pp.86-89
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The performance of traditional routing protocols for mesh networks can decrease significantly in disaster recovery situations due to dynamic changes to the network environment. A number of multi-path routing protocols have been proposed to address such issues. MMQR is a multi-path routing protocol for OFDM?TDMA mesh networks which use multiple paths that can be replaced immediately by one another in case of link failures. In this paper we extend the MMQR such that the alternative paths are reordered adaptively as the communication environment changes based on the heuristic model of attractor selection mechanism by which biological entities are known to adapt to dynamically changing environment. Simulation results show that the multi-path routing protocol with attractor selection mechanism outperforms existing multi-path routing protocols in terms of packet delivery ratio, throughput and QoS.
Mobile Ad Hoc Network에서 테이블 기반 경로 관리를 이용한 역추적 기법 KCI 등재
한국융합보안학회 융합보안논문지 제13권 제1호 2013.03 pp.19-24
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 이동 노드로만 구성되어 있기 때문에 매우 동적인 토폴로지를 갖는다. 이러한 특성을 이용한 다양한 공 격 위협이 존재하고 있으며 그 중에서 DoS나 DDoS 같은 플러딩 기반 공격의 피해가 매우 크고 공격 노드의 역추적 역시 쉽지 않다. 왜냐하면 데이터를 전달해준 중간 노드들의 이동으로 경로 정보가 수시로 변화하기 때문이다. 본 논문 에서는 노드들의 이동으로 인한 경로 정보가 수시로 변화하더라도 효율적인 역추적을 수행할 수 있도록 테이블 기반 역추적 기법을 제안하였다. 클러스터 헤드에서는 클러스터 멤버 노드에 변화가 생겼을 때 이동 노드들의 위치 정보를 저장하기 위한 클러스터 상태 테이블과 네트워크 토폴로지 스냅샷을 구성하기 위하여 경로 관리 테이블을 관리한다. 또 한 저장되는 경로 정보의 양을 줄이기 위하여 블룸 필터를 이용하였다. 제안한 기법의 성능을 실험을 통해 확인하였다.
MANET has a highly dynamic topology because it consists of only mobile nodes. Various attacks using these characteristics exist. Among them, damage of the attacks based flooding such as DoS or DDos is large and traceback of the attack node is not easy. It is because route information by moving of intermediate nodes which pass the data changes frequently. In this paper, we propose table-based traceback technique to perform efficient traceback although route information by moving of nodes changes frequently. Cluster head manages route management table in order to form cluster status table and network topology snapshot for storing the location information of mobile nodes when cluster member nodes change. Also, bloom filter is used to reduce the amount of storing route information. The performance of the proposed technique is confirmed through experiment.
Mobile Ad-hoc Network에서 캐싱 관리 기법에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제12권 제4호 2012.09 pp.91-96
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
무선 네트워크의 많은 분야 중에서 MANET(Mobile Ad-hoc Network)은 상당히 발전이 되어있는 기술이다. MANET을 구성하는 노드들은 다중 홉 무선 연결을 이용하여 데이터 전달을 하게 된다. 이러한 환경에서 노드들의 데 이터 접근 성능과 가용성을 향상시킬 수 있는 방법이 캐싱 기법이다. 기존의 많은 연구들은 이동 노드들의 다중 홉 연 결을 향상시키기 위해 동적인 라우팅 프로토콜에 대해 많은 연구가 이루어져왔다. 그러나 노드들의 이동으로 인하여 유 효한 캐시 정보의 관리 및 유지가 쉽지 않다. 본 논문에서는 이동 노드가 원하는 정보의 캐시 발견시 오버헤드를 줄이 고 노드들의 이동으로 인한 연결 관리를 위해 클러스터 기반 캐싱 기법을 제안하였다. 그리고 각 클러스터 헤드에서 유 효한 캐시 테이블을 유지할 수 있도록 하기 위해 HLP를 이용하였다. 본 논문에서 제안한 기법의 효율성은 실험을 통해 확인하였다.
MANET is developed technique fairly among many field of wireless network. Nodes which consist of MANET transmit data using multi-hop wireless connection. Caching scheme is technique which can improve data access capacity and availability of nodes. Previous studies were achieved about dynamic routing protocol to improve multi-hop connection of moving nodes. But management and maintenance of effective cache information because of movement of nodes is not easy. In this study, we proposed cluster-based caching scheme to manage connection by decreasing overhead and moving of nodes as moving node discovers cache of wish information. And HLP was used to maintain effective cache table in each cluster head. Efficiency of proposed technique in this study was confirmed by experiment.
Mobile Ad-Hoc Network를 활용한 교통 정보 시스템
한국ITS학회 한국ITS학회 학술대회 2006년 한국ITS학회 추계학술대회 및 정기총회 2006.10 pp.290-294
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Mobile Ad-hoc Network for Network Mobility (MANEMO) 기술
한국컴퓨터통신연구회 OSIA Standards & Technology Review Journal 제31권 제1호 통권69호 2008.03 pp.28-36
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET 환경에서의 DDoS 공격방지 알고리즘 분석 KCI 등재
한국융합보안학회 융합보안논문지 제13권 제1호 2013.03 pp.11-17
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문에서는 MANET(Mobile Ad-hoc Network) 환경에서의 보안 요구사항과 DDoS(Distributed Denial of Service) 공격방지를 위한 보호노드(게이트웨이) 설정 알고리즘을 제시한다. 이를 위하여, 정보보호를 위한 기반 기술 및 네트워크 응용기술과 보안위협을 분석하고 MANET에서 필수적으로 요구되는 보안 요구사항을 제시하 며, 송신과 수신노드 사이 정보전달시 DDoS 공격을 효과적으로 방어하기 위한 보호노드 설정 알고리즘을 제시하 고 성능을 분석한다. 보호노드 설정시 보호노드와 수신노드들 사이의 총링크 비용의 최대값을 최소화하는 경우와 평균비용을 최소화하는 경우로 구분하여 성능을 분석하며, 각 알고리즘의 성능을 All Enumeration 기법을 이용하 여 구한 최적해와 비교, 분석한다. 분석결과, 보호노드와 수신노드들 사이의 최대비용을 이용하는 경우보다 평균 비용을 이용하여 보호노드를 설정하는 경우 송신과 수신 노드들 사이의 총비용이 최소화됨을 알 수 있다.
In this paper, the information security requirements in the mobile ad-hoc network(MANET) are presented, and the algorithm to establish the protection node(gateway) is proposed to prevent the distributed denial of se rvice(DDoS). The information security technology and security threats in the MANET are presented, and prot ection node is decided to minimize the total cost through the sending nodes and receiving nodes by way of pr otection node. To set up the protection node, the minimization algorithms of maximum cost and the average c ost between the protection node and receiving nodes are compared with the optimal solutions, in which optim al solution is found out by all enumeration method. From the results, the total cost between the sending and receiving nodes is minimized under the average cost minimization algorithm rather than the using of the maxi mum cost.
이동 Ad-hoc 네트워크에서의 트래픽 관리에 관한 연구
대한안전경영과학회 대한안전경영과학회 학술대회논문집 변화와 안전경영 2002.05 pp.121-127
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
In this paper, we propose traffic management support and evaluate the performance through simulation. We suggest traffic management routing protocol that can guarantee reliance according to not only reduction of the Network traffic congestion but also distribution of the network load that prevents data transmission. For performance evaluation, we analyzed the average data reception rate and network load, considering the node mobility. We found that in the mobile Ad Hoc networks, the traffic management service increased the average data reception rate and reduced the network traffic congestion and network load in Mobile Ad Hoc Networks.
이동 애드혹 네트워크에서 개선된 AODV 라우팅 프로토콜에 관한 연구
대한안전경영과학회 대한안전경영과학회 학술대회논문집 안전경영과 비젼 2002.11 pp.261-267
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
화재나 긴급상황이 발생하였을 때 임시적으로 네트워크를 구성할 수 있는 애드혹 네트워크분야에서 DSR, AODV, TORA, ZRP 라우팅 프로토콜의 연구가 활발하며 이에 대한 여러가지 개발이 이루어지고 있다. 본 논문에서는 AODV 라우틸 프로토콜을 이 용하여 다양한 네트워크 환경에서 AODV 라우팅 프로토콜의 성능평가와 함께 AODV 라우팅 프로로콜의 문제점을 수정하여 개선하여 실질적인 MANET 통신에서 사용될수 있는 라우팅 프로토콜을 제안한다.
무선 애드혹 망에서 클러스터 기반 DDoS 탐지 기법에 관한 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제11권 제6호 2011.12 pp.25-30
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 이동 노드로만 구성되어 있고 중앙 관리 시스템이 존재하지 않기 때문에 보안에 더욱 취약한 구조를 가지고 있다. 이러한 무선 네트워크를 위협하는 공격들 중에 그 피해가 가장 심각한 공격이 바로 DDoS 공격이다. 최근 들어 DDoS 공격은 목표 대상과 수법이 다양해지고 지능화 되어가고 있다. 본 논문에서는 비정상 트래픽을 정확히 분류하여 DDoS 탐지율을 높이기 위한 기법을 제안하였다. MANET을 구성하는 노드들을 클러스터로 형성한 후 클러스터 헤드가 감시 에이젼트 기능을 수행하게 하였다. 그리고 감시 에이젼트가 모든 트래픽을 수집한 후 비정상 트래픽 패턴을 탐지하기 위하여 결정트리 기법을 적용하였으며 트래픽 패턴을 판단하여 공격을 탐지하였다. 실험을 통해 본 논문에서 제안한 탐지 기법의 높은 공격 탐지율을 확인하였다.
MANET has a weak construction in security more because it is consisted of only moving nodes and doesn't have central management system. The DDoS attack is a serious attack among these attacks which threaten wireless network. The DDoS attack has various object and trick and become intelligent. In this paper, we propose the technique to raise DDoS detection rate by classifying abnormal traffic pattern. Cluster head performs sentinel agent after nodes which compose MANET are made into cluster. The decision tree is applied to detect abnormal traffic pattern after the sentinel agent collects all traffics and it judges traffic pattern and detects attack also. We confirm high attack detection rate of proposed detection technique in this study through experimentation.
Multi-level 구조를 이용한 보안 라우팅 프로토콜에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제14권 제7호 2014.12 pp.17-22
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
MANET은 빠르게 네트워크를 구축할 수 있다는 특징 때문에 많은 분야에서 활용되고 있다. 그러나 무선 네트워크의 특성과 노드들의 이동으로 인해 많은 보안 위협에 노출되어 있다. 특히 그중에서도 라우팅 프로토콜의 취약점을 이용한 공격이 증가하고 있으며 그 피해 또한 매우 증가하고 있는 설정이다. 본 논문에서는 안전한 라우팅 프로토콜 제공을 위한 two-level 인증 구조를 제안하였다. 제안한 기법에서는 네트워크에 참여하는 노드들에 대하여 신뢰도를 기반으로 한 인증 평가를 실시하여 인증서를 발급해주며, 인증서를 발급받은 노드만이 데이터 전송을 수행하게 된다. 그리고인증서를 발급받은 노드가 데이터 전송시 제어 패킷의 정보와 자신이 관리하는 PIT 정보를 비교 및 분석하여 악의적인노드들에 대한 탐지를 수행하게 된다. Ns-2 시뮬레이터를 이용하여 본 논문에서 제안한 기법의 성능을 평가하였으며,실험을 통하여 우수한 성능을 확인하였다.
Wireless Ad hoc Network is threatened from many types of attacks because of its open structure, dynamictopology and the absence of infrastructure. Attacks by malicious nodes inside the network destroy communicationpath and discard packet. The damage is quite large and detecting attacks are difficult. In this paper, we proposedattack detection technique using secure authentication infrastructure for efficient detection and prevention of internalattack nodes. Cluster structure is used in the proposed method so that each nodes act as a certificate authority andthe public key is issued in cluster head through trust evaluation of nodes. Symmetric Key is shared for integrity ofdata between the nodes and the structure which adds authentication message to the RREQ packet is used. ns-2simulator is used to evaluate performance of proposed method and excellent performance can be performed throughthe experiment.
군 전술통신네트워크를 위한 비밀분산 및 ECC 기반의 공개키 인증 기법 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.13 No.6 2016.12 pp.421-438
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
군 전술통신환경은 자원제약적인 특성을 가지기 때문에 기존 네트워크에 적용하는 인증기관에 의한 공개키 기반 사용자 인증을 적용하기가 제한된다. 본 논문에서는 이러한 문제점을 해결하기 위하여 비밀분산기법을 적용하여 인증기관이 없는 공개키 기반 사용자 인증체계를 제안하였다. 이 기법은 Shamir의 (t, n) 임계치 기법과 지수 분산정보를 적용하여 전술 단말기가 악의적인 공격자에 의해 탈취되더라도 네트워크의 안전성을 보장하도록 설계하였다. 추가적으로 타원곡선 암호시스템을 적용하여 단말기의 자원 효율성을 보장하고, 군 전술통신환경에 요구되는 보안성과 신뢰성을 확립하였다.
Military tactical communication environment that have a resource constraint characteristics limited to applying the public key based user authentication by the Certificate Authority(CA). In this paper, we propose a certificate-less public key based user authentication scheme by applying the secret sharing scheme in order to solve such problems. Our approach applied a Shamir's (t, n) threshold secret sharing scheme and transformed share is designed to be able to ensure the safety of the network although some tactical nodes were held by a malicious attacker. In addition, we also apply the elliptic curve cryptosystem to ensure the resource efficiency of the node and establish the reliability and enhanced security required in Military tactical communication environment.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.