15
A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu, Hiroki Nishiyama, Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Embed Size (px)

Citation preview

Page 1: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu, Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011

Nadia Adem 10/27/2014

Page 2: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Attacks in MANEN• Self-organized • Wireless • Dynamic

Security attacks

Certificates

Isolation

Promptly

Accurately Revoked Accused

Page 3: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Outline• Some MANETS security schemes• Clustering-based scheme• Scheme main idea • The way it works• Issues • Performance Analysis• Contributions• Weak aspects

• Summary

Page 4: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

MANET Security Schemes

• Certificate control approach-CA • Digital certificate expires • Valid certificate nodes- certificates revoked

• Voting-based scheme- NO CA• Nodes vote - variable weight• Ticket revoked

• Suicide-based approach- NO CA• Node sacrifice itself

Page 5: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Clustering-based Scheme

False Accusation

Malicious Attack

Overhead communications

Time

Page 6: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

How does it work?

CA

CM2

CH

CM1CM2CH CM1

CM2CM1

ADP CRP

CM2CH CM1

CM3

detect false

accusations

Quick revocation/recoverySmall overheadResolve false accusation/recovery

Page 7: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Issues and SolutionsAccuser nodes Warned

Recovery

requester

Can not accuse

Page 8: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Node Release Method

• Threshold approach• Accuser in warning list till K nodes or more accuse the accused

node

AccuserMISBEHAVING

LEGITIMATE

Page 9: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Performance EvaluationSimulation Parameters

Parameter Value

Number of nodes 50 normal nodes and 10 - 60 malicious nodes

Mobility model Random-Waypoint

Node placement Random

Routing protocol AODV

Pause time 5 sec

Transmission range 250 m

Terrain dimensions 1 km2

Page 10: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Performance Evaluation

Page 11: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Performance Evaluation

Node release threshold sch. Applied Not applied

Page 12: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Performance Evaluation

False accusations

Threshold

Detection time

Page 13: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Contributions • Quickly revoke certificates of accused nodes • Distinguish false accusation• Restore a node’s accusation ability

Page 14: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Weak Aspects• Existence of CA• Threshold determination

• Malicious nodes communicate with all other nodes in the cluster!

Page 15: A Study on Certificate Revocation in Mobile Ad Hoc Networks Wei Liu,Hiroki Nishiyama,Nirwan Ansari & Nei Kato ICC 2011 Nadia Adem 10/27/2014

Summary• Security Scheme for MANETs • Certificate revocation scheme • Advantages• Performance • shortcoming