Need to reduce the plagiarism percentage to 0%. work is already done.

profileAamer440
DocumentationPlagiarisedandSorted.docx

IDENTIFICATION OF MULTIPLE MALICIOUS NODES IN MANETS

Abstract:

Mobile ad-hoc network is a self-organizing, infrastructure less network in which mobile nodes communicate using wireless channel. In MANET, the network created by the mobile nodes is dynamic in nature i.e. it is not confined to a particular topology because devices are free to move independently. Since there is no centralized node for monitoring in MANET routing path needs to be found dynamically. In this project we propose a novel top-k query approach to detect multiple malicious by implementing a route reply reverse tracing technique to help in achieving the stated goal. Proposed system helps us in defending against the multiple attack without any requirement of hardware and special detection node

CHAPTER 1

INTRODUCTION

1.1 GENERAL:

MOBILE AD-HOC NETWORKS:

An ad-hoc community may be a collection of Wi-Fi cellular hosts forming a quick lived network at the same time as now not the assist of any whole infrastructure or centralized management. The Mobile Ad-hoc networks region unit self-organizing and self re-configuring a multihop wireless networks anywhere, the shape of the network modifications dynamically. This may be in the predominant attributable to the nice of the nodes. Nodes in these networks utilize an equivalent random access wireless channel, cooperating in a pleasant way to enticing themselves in multihop forwarding. The nodes within the community, that are not most effective, act as hosts but also as routers that course records to/from different nodes in community.

In mobile ad-hoc networks wherein there's no infrastructure assist as is the case with wireless networks, and considering a vacation spot node is probably out of range of a supply node transmitting packets; a routing method is always needed to find a course if you want to ahead the packets as it should be among the supply and the vacation spot. Within a mobile, a base station can reach all cell nodes without routing through broadcast in not unusual wireless networks. In the case of ad-hoc networks, each node ought to be capable of being ahead of the facts for other nodes. This creates additional issues in conjunction with the problems of dynamic topology that's unpredictable connectivity adjustments.

MANETS depend upon Wi-Fi transmission, a secured manner of message transmission is vital to protect the privacy of the facts. An insecure ad-hoc network at the threshold of a current communication infrastructure can also probably cause the whole community to grow to be susceptible to security breaches. In cell advert hoc networks, there may be no valuable administration to attend to detection and prevention of anomalies.

Mobile devices identities or their intentions can't be predetermined or demonstrated. Therefore nodes ought to cooperate for the integrity of the operation of the community. However, nodes may additionally refuse to cooperate through no longer forwarding packets for others for selfish reasons and no longer want to exhaust their assets.

Various other elements make the challenge of secure conversation in ad hoc Wi-Fi networks tough include the mobility of the nodes, a promiscuous mode of operation, limited processing power, and restricted availability of sources consisting of battery power, bandwidth and memory. Therefore nodes ought to cooperate for the integrity of the operation of the network. Nodes can also refuse to cooperate by now not forwarding packets for others for egocentric reasons and no longer want to exhaust their resources.

In ad hoc networks gadgets (also known as nodes) act each as computer systems and routers. Most routing protocols lead nodes to trade network topology statistics with a view to establish communication routes. This fact is sensitive and will become a target for malicious adversaries World Health Organization shall attack the network or the applications walking on that. There vicinity unit 2 assets of threats to routing protocols. The number one comes from outside attackers. By injecting wrong routing information, replaying latest routing records, or distorting routing facts, Associate in Nursing perpetrator might also with achievement partition a network or introduce a site visitors overload through inflicting retransmission and inefficient routing. The second and a whole lot of extreme fairly hazard comes from compromised nodes, which could (i) misuse routing statistics to unique nodes or (ii) act on practical facts with a purpose to induce service failures.

The provision of systematic processes to decide the impact of such threats on specific routing protocols stays Associate in Nursing open task in recent times. Attacks on the impromptu place unit categorized into non-tumultuous passive attacks and tumultuous lively attacks. The lively assaults location unit extra categorized into inner attacks and external assaults vicinity unit disbursed by means of nodes that don't belong to network and might be prevented by using firewalls and coding strategies. Internal assaults place unit from internal nodes which might be actually certified nodes and part of the community thence it's troublesome to identify.

MOBILE ad hoc networks (MANETs) represent complex distributed systems that consist of wireless mobile nodes that can dynamically and freely self-organize into arbitrary and temporary ad hoc network topologies . This allows people and devices to seamlessly internetwork in areas where no pre-existing communication infrastructure exists, for example disaster recovery environments. The unique characteristics of MANETs, such as dynamic topology and resource constraint devices, pose a number of nontrivial challenges for efficient and lightweight security protocols design. Due to the lack of centralized identity management in MANETs and the requirement of a unique, distinct, and persistent identity per node for their security protocols to be viable, DoS attacks pose a serious threat to such networks.

A DoS attacker can cause damage to the ad hoc networks in several ways . For example, a Sybil attacker can disrupt location based or multipath routing by participating in the routing, giving the false impression of being distinct nodes on different locations or node-disjoint paths. A chance to consider a reason for pernicious node attacking top-k inquiry handling. Fundamentally, noxious nodes endeavor to disturb inquiry issuing node's obtaining of the worldwide top-k result for a long stretch, without being distinguished. In any case, DoS attacks in MANETs have been effectively concentrated on for long years, and subsequently, utilizing existing methods, such attacks can be uncovered by the question issuing node then again middle nodes. Here, a wonderful normal for topk question handling is that the inquiry issuing node does not know the worldwide top-k come about heretofore.

1.1.1 APPLICATION AREAS:

Some of the packages of MANETs are

• Military or police bodily video games.

• Disaster alleviation operations.

• Mine net page operations.

• Urgent Business conferences

• Robot information acquisition

It is simple to anticipate some of programs wherein this kind of homes may want to deliver blessings. One interesting studies region is inter-car communications. It is one vicinity in which the advert hoc networks need to absolutely trade the manner we talk covering non-public automobiles as well as expert mobile verbal exchange desires. Also, it's miles vicinity wherein no conventional (i.e. wired) answers ought to do because of the excessive degree of mobility.

When considering demanding environment, say mines as an instance, then neither would the bottom station technique paintings however we need to have the potential to perform routing via nodes which can be part of the community i.e. we should use advert hoc network. Such networks may be used to allow subsequent generation of battlefield programs anticipated with the resource of the military inclusive of scenario popularity systems for maneuvering battle fighters, and remotely deployed unmanned micro-sensor networks.

Ad Hoc networks can provide verbal exchange for civilian programs, collectively with disaster recuperation and message exchanges among scientific and protection personnel involved in rescue missions.

1.1.2 ADVANTAGES:

The following are the advantages of MANETs:

· They offer get right of entry to to facts and offerings irrespective of geographic position.

· These networks may be installation at any vicinity and time.

· These networks paintings with none pre-present infrastructure.

Figure: Disaster relief operations

Figure: Military or police exercises

1.2 OBJECTIVES OF THE STUDY:

In this challenge, our goal is to save you information from attackers in mobile advert-hoc community and to emerge as aware of the malicious nodes through query issuing nodes that are near their very own location, while they infrequently understand the malicious nodes which may be some distance from their non-public region.

1.2.1 SOFTWARE & HARDWARE NECESSITIES:

HARDWARE:

· Single PC with

· 20 Gb Hard disc place

· 1Gb RAM

SOFTWARE:

· Linux OS (Ubuntu 10.04)

· NS2.34

LANGUAGES:

· TCL(Front cease type mission only)

· Python (Optional)

· C++ (Optional)

NS2:

During the final decade, there had been a whole lot of studies and works produced bearing on the software program software, protocols, network kinds, network factors, and visitors models. Most of those research and works have been based on the use of simulators. Network simulator ns-2 has been the most used network simulator for the only studies. Most mobile advert-hoc research agencies rent the ns-2 to position into effect and validate several algorithms as it gives a kind of integration surroundings. The virtual surroundings furnished by way of manner of simulation makes it a rather beneficial method for a series of favorite tendencies, which incorporates network modeling relying on unique requirements and studying its average overall performance underneath awesome conditions.

NS2 is an open-supply event-driven simulator designed especially for studies in laptop communication networks. Since its inception in 1989, NS2 has continuously received amazing interest from an business enterprise, academia, and government. Having been beneath constant research and enhancement for years, NS2 now includes modules for numerous network components which consist of routing, transport layer protocol, software program utility, and masses of others. To take a look at our network usual overall performance, researchers can sincerely use an easy-to-use scripting language to configure a community and feature a observe results.

Network simulator ns-2 can be defined as a simulator that is written in languages, C++ and OTCL (item-oriented tool command language), with the concept of item orientated. The topology of simulation is written in TCL, and it is been related to the modules of the simulator which can be written in C++ via the use of OTCL linkages (the regularly occurring functioning may be represented inside the figuring out below). The method of mistakes debugging have turn out to be extra complicated with ns-2, and it's far taken into consideration to be a disadvantage with using this simulator, thinking about that there may be a combination of languages with this simulation.

1.2.2 MODEL OUTPUT:

· Nam window

· X-Graph.

TCL:

Tool Command Language is used for loads of hundreds of people within the actual global. It is a language with quite easy syntaxes and it lets in a completely easy integration with different languages. TCL changed into created by using Jhon Ousterhout.

The trends of this language are:

· It permits a quick development.

· It provides a photograph interface.

· It is compatible with many structures.

· It is flexible for integration.

· It is free and easy to apply.

OTCL:

OTCL typically refers to an object oriented extension of TCL created with the beneficial useful resource of David Wetherall. It is utilized in network simulator (ns-2) and generally run beneath UNIX environment.

SUDO:

The Super-User DO its miles an application for some Unix and Unix-like laptop running structures that permits customers to run programs with the safety privileges of a few other users (generally the super user, or root).

APT:

The Advanced Packaging Tool or APT is one of the free purchasing interfaces that work with middle libraries to address the setup and also the removal of software program software at the Debian GNU/Linux distribution and most of its variants. APT simplifies the technique of handling a software program application to program on Unix-like PC structures by means of the usage of automating the retrieval, configuration, and set up of the software and software program applications, both from the binary files and by using compiling supply code.

TCLCL:

(TCL with education) is a TCL/C++ interface which has become utilized by Mash, vic, vat, rtp_play, ns, and nam. It also offers a layer of C++ glue over OTCL.

CHAPTER 2

LITERATURE REVIEW

2.1 EXISTING SYSTEM:

· In an Edouard MANET, every node receiving data, nodes furthermore need cooperation with one another to prior to the information packets, thereby forming a Mobile-advert-hoc community.

· DSR doesn't have any detection mechanism, but the provision node will get all path data concerning the nodes on the route.

· In our challenge tool is to shield con to the assaults through employing a few technique. Within the malicious node identification technique, drop the packets and given the pretend replay at constant time as received with m.

· Maintain the packets.

· Therefore, we tend to estimate that malicious nodes do DoS, that malicious nodes update essential statistics devices with useless however correct facts devices.

· The presence and collaboration of malicious nodes among the network could boot disrupt the routing technique, vital to an awry of the community operations.

· In our methodology, we tend to rent this feature. During this paper, a mechanism pinnacle-adequate question process approach is offered that effectively detects the malicious nodes that conceive to unharness a DoS attacks.

DISADVANTAGES:

· Malicious nodes discard these packets without forwarding them to the vacation spot.

· Malicious node can attract all packets by way of the use of solid Route Reply.

· Increased congestion.

· Cannot detect multiple malicious nodes in the network

2.2 PROPOSED SYSTEM:

The malicious node identification structured in three different stages such as 1. The initial query issuing node step;2. The reverse tracing step;3. The shifted to reactive defense step, The first two steps are initial proactive defense steps, whereas the third step is a reactive defense step. A. Initial query node Step The goal of the query node phase is to entice a malicious node to send a reply RREP by sending the query node RREQ’ that it has used to advertise itself as having the shortest path to the node that detains the packets that were converted.

The reverse tracing step is used to detect the behaviors of malicious nodes through the route reply to the RREQ’message. If a malicious node has received the RREQ’, it will reply with a false RREP. Accordingly, the reverse tracing operation will be conducted for nodes receiving the RREP, with the goal to deduce the dubious path information and the temporarily trusted zone in the route.

After the above initial proactive defense (steps A and B), the DSR [10] route discovery process is activated. When the route is established and if at the destination it is found that the packet delivery ratio significantly falls to the threshold, the detection scheme would be triggered again to detect for continuous maintenance and real-time reaction efficiency.

2.2.1 APPLICATIONS OF THE PROPOSED SYSTEM

· Help in preventing or averting an assault in its initial level.

· It can perceive all the addresses of nodes inside the selected routing route from a source to vacation spot after the supply has received the RREP message.

· Improve packet delivery price.

· Reduced the overhead.

· Can detect multiple malicious nodes in a single query

CHAPTER 3

METHODOLOGY/IMPLEMENTATION

3.1 METHODOLOGY

The proposed model organized into different processes such as Forwarding, Detection, and identification process.

3.1.1 QUERY FORWARDING AND REPLY PROCESS

The query-issuing node broadcasts a query on over the network it consist of query issuing node id, the number of data items k, query condition, Query path . particularly, the query-issuing node Mp, denotes the query condition and the number of requested data items, k. Then, Mp broadcasts a query message whose Query path includes its identifier, Mp, to its neighbour nodes. According to the Query Forwarding Algorithm, the hop count represents the total number of hops, based on the number of nodes included in the Query path the waiting time for reply RD measured by following equation

denotes the maximum ho*s and number of ho*s from querying node. is a +ve constant. After receiving a query message from querying node, the mobile node reply to the querying node, which it consist of node_id,reply route,list of data items and the node identifiers of the nodes possessing them (Data list), and a reply message routes list, i.e., a

Algorithm 1- Query Forwarding

1: /* Receive a query message */

2: if Mq receives a query for the _rst time then

3: Store Query path and hop counts as its Parent Query

path

4: Store the node ID at the end of Query path as its parent

5: Set RD for replying data items

6: /* Send the query message to neighbour nodes */

7: Add M0q

s node ID to the end of Query path

8: Send the query to neighbour nodes

9: else

10: Store Query path and hop count as its Neighbour Query

path

11: Store the node ID at the end of Query path as its

neighbour

12: end if

In reply message algorithm, the node Mr sends a reply message when its RD has passed. Here, REP signifies an reply message what's more, REP. FR signifies the sending course list comprising of (Sender hub ID, Dest hub ID), which means the rundown of sender and next node identifier sets, and R means the most extreme number of reply messages to be re-sent. Mr chooses the following node from its neighbouring nodes, which has the slightest bounce check and slightest cover between its Query way and the parent node's Query way

Algorithm 2- Sending a Re*ly message

1: /* Sends a reply message after RD has elapsed */

2: /* Select a node to send a reply message */

3: for each Neighbour do

4: if Neighbour's hopCount is the minimum then

5: Insert Neighbour into DestNode

6: end if

7: end for

8: if jDestNodej > 1 then

9: Select a Neighbour whose Neighbour Query path least

overlaps with the parent Query path as a DestNode

10: end if

11: Add the local top-k result to REP

12: for i D 0 to 1 do do

13: if i D 0 then

14: Add (Mr , parent node) to received REP.FR and send

REP to parent node

15: else if i D 1 then

16: Add (Mr , DestNode) to received REP.FR and send

REP to DestNode

17: end if

18: end for

19: /* Receive a reply message */

20: Send ACK to the sender node of REP

21: if before RD then

22: Store REP

23: else if after RD and Mr receives a data item with higher

score than with the kth-highest score among data items

already sent then

24: Send REP including new local top-k result to parent

node and DestNode

25: end if

26: /* Resend the reply message */

27: if Mr does not receive ACK from its parent by waiting

time for retransmission and the number of retransmis-

sions < R then

28: Resend REP to parent

29: else if Mr does not receive ACK from DestNode by wait-

ing time for retransmission and the number of retrans-

missions < R then

30: Resend REP to DestNode

31: else if the number of retransmissions > R then

32: /* Mr detects the disconnection of radio link */

33: if Mr has sent REP to all Neighbour then

34: Discard REP

35: else if Mr knows a Neighbour whose Neighbour Query

path includes DestNode then

36: Send REP to the Neighbour

37: else

38: Select randomly a Neighbour among Neighbours

which have not been selected yet

39: Send REP to the Neighbour

40: end if

41: end if

3.1.2 DETECTION

After the query-issuing node, Mp, receives all the reply messages, it detects a DRA according to Detection attack Algorithm. Each node calculates the local reputation scores of other nodes from correctness of received files, and foods the score information in the network. Then, each node calculates the global reputation score from its own and received local scores. At last, it determines the node whose global score is lower than a threshold as the malicious nodes. In have proposed methods in which each node manages the reputation values of its neighbouring nodes in MANET.

Algorithm – Attack Detection

1: /* After the query-issuing node receives all reply mes-

sages */

2: INPUT: Top-k Result, REPs

3: OUTPUT: SendRoute

4: SendRoute ;

5: for each REP do

6: for each Top-k Result do

7: if REP.FR includes the node ID of a node processing

a data item in Top-k Result and REP.Data does not

include the data item then

8: Insert a route from the node with the missing data

item to the query-issuing node into SendRoute

9: end if

10: end for

11: end for

12: if SendRoute 6D ; then

13: Detect Attack

14: end if

3.1.3 MALICIOUS NODE IDENTIFICITION

The malicious node identification structured in three different stages such as 1. The initial query issuing node step;2. The reverse tracing step;3. The shifted to reactive defense step, The first two steps are initial proactive defense steps, whereas the third step is a reactive defense step. A. Initial query node Step The goal of the query node phase is to entice a malicious node to send a reply RREP by sending the query node RREQ’ that it has used to advertise itself as having the shortest path to the node that detains the packets that were converted. To achieve this goal, the following method is designed to generate the destination address of the query node RREQ’. The source node stochastically selects an adjacent node, i.e., nr , within its one-hop neighbourhood nodes and cooperates with this node by taking its address as the destination address of the query node RREQ’.

Since each query nodeing is done stochastically and the adjacent node would be changed if the node moved, the query node would not remain unchanged. This is illustrated in Fig. 1. If nr deliberately gave no reply RREP, it would be directly listed on the black hole list by the source node. If only the nr node had sent a reply RREP, it would mean that there was no other malicious node in the network, except the route that nr had provided; in this case, the route discovery phase of DSR will be started. The route that nr provides will not be listed in the choices provided to the route discovery phase.

Fig 1: Malicious node identification

Reverse Tracing Step The reverse tracing step is used to detect the behaviors of malicious nodes through the route reply to the RREQ’ message. If a malicious node has received the RREQ’, it will reply with a false RREP. Accordingly, the reverse tracing operation will be conducted for nodes receiving the RREP, with the goal to deduce the dubious path information and the temporarily trusted zone in the route.

C. Reactive Defence Step After the above initial proactive defense (steps A and B), the DSR [10] route discovery process is activated. When the route is established and if at the destination it is found that the packet delivery ratio significantly falls to the threshold, the detection scheme would be triggered again to detect for continuous maintenance and real-time reaction efficiency. The threshold is a varying value in the range [85%, 95%] that can be adjusted according to the current network efficiency. The initial threshold value is set to 90%. We have designed a dynamic threshold algorithm that controls the time when the packet delivery ratio falls under the same threshold. If the descending time is shortened, it means that the malicious nodes are still present in the network. In that case, the threshold should be adjusted upward. Otherwise, the threshold will be lowered.

Fig 2: Malcious node reply Tracking Flow Chart

3.2TESTING AND DEBUGGING

Testing and debugging a program is one in every of the foremost

tedious components of computer programing. The testing and debugging part of a

project will simply take longer than it took to write down the applying. Testing

includes each checking that the code runs in the least, that it runs properly underneath all

circumstances, which it runs a similar manner it did before you created changes. TCL's

error medical specialty create it simple to trace down writing errors; the standard nature of

TCL code makes it simple to try and do unit testing of functions, and also the TCL take a

look at package makes it simple to write down integrated regression take a look at suites.

3.2.1 DEBUGGING CODE

The first step to debug a TCL script is to study the TCL error output thoroughly. TCL

provides information about verbose error that directs us to view the exact line where a coding

error occurs. TCL error messages consist of a set of lines. The first line directs us to

immediate cause of the error. The rest of the code describes details about where the error

occurs. For example, this system has a common error - the closing brace and bracket are

wrongly ordered.

CHAPTER 4

PERFORMANCE EVOLUTION, RESULTS

4.1 PERFORMANCE EVOLUTION

The ns-2 simulation tool is used to study the performance of our top-k scheme. We employ the IEEE 802.11 MAC with a channel data rate of 11 Mb/s. In our simulation, the top-k default threshold is set to 90%. All remaining simulation parameters are captured in Table I. The network used for our simulations is depicted in Fig. 5; and we randomly select the hostile nodes to perform attacks in the network.

We use Network Simulator Version-2 (NS2) [15] to simulate our proposed algorithm. In our simulation, the channel capacity of mobile hosts is set to the same value: 2 Mbps. We use the distributed coordination function (DCF) of IEEE 802.11 for wireless LANs as the MAC layer protocol. It has the functionality to notify the network layer about link breakage.

In our simulation, mobile nodes move in a 1000 meter x 1000 meter region for 25 seconds simulation time. All nodes have the same transmission range of 250 meters. The simulated traffic is Constant Bit Rate (CBR). Our simulation settings and parameters are summarized in table 1

No. of Nodes

50

Area Size

1000 X 1000

Mac

802.11

Radio Range

250m

Simulation Time

25 sec

Traffic Source

CBR

Packet Size

512

Receiving Power

0.395

Sending power

0.660

Idle Power

0.035

Initial Energy

10.3 J

Rate

50,100,150,200 and 250Kb

Table 1: Simulation Settings

We evaluate mainly the performance according to the following metrics.

Average Packet Delivery Ratio: It is the ratio of the number .of packets received successfully and the total number of packets transmitted.

Average Routing overhead: It is the average number of routing packets by nodes.

Delay: It is the time taken by the packets to reach the receiver.

Avg Throughput: It is the amount of successful message delivery over a node

4.2 RESULTS:

Our top-k scheme shows a higher packet delivery ratio compared with that of Existing model. Even in the case where 40% of the total nodes in the network are hostile, the novel top-k scheme still successfully detects those hostile nodes while keeping the packet delivery ratio above 90%. A threshold of 95% would then result in earlier route detection than when the threshold is 85% or is set to the dynamic threshold value. Thus, the packet delivery ratio when using a threshold of 95% is higher than that obtained when using a threshold of 85% or the dynamic threshold. Second, we study the routing overhead of the novel top-k and DSR for different thresholds. The results are captured in Fig. 6. In Fig. 6, it can be observed that when the number of malicious nodes increases, DSR produces the lowest routing overhead compared with the novel top-k. This is attributed to the fact that DSR has no intrinsic security method or defensive mechanism. In fact, the routing overhead produced by the novel top-k for different thresholds is a little bit higher than that produced by DSR; this might be due to the fact that the novel top-k would first send bait packets in its initial bait phase and then turn into a reactive defensive phase afterward. Consequently, a tradeoff should be made between routing overhead and packet delivery ratio. We have studied the effect of thresholds on the routing overhead. As expected, it was found that the routing overhead of the novel top-k reaches the highest value when the threshold is set to 95%. This is attributed to the fact that the detection scheme of novel top-k triggers fast when the threshold value is 95% compared with when it is set to 85% or when it is equal to the dynamic threshold value. Thus, the bait packets will be sent many times in the network. It should be noticed that the dynamic threshold value can be adjusted according to the network performance.

F:\2017students\GNIT\nisma\topk\topk\pdr.png

Fig 3- Attacks vs Delivery Ratio

F:\2017students\GNIT\nisma\topk\topk\ec.png

Fig 4- Attacks vs Energy Consum*tion

F:\2017students\GNIT\nisma\topk\topk\delay.png

Fig 5- Attacks vs End to End Delay

F:\2017students\GNIT\nisma\topk\topk\throughput.png

Fig 6- Attacks vs Avg Throughput

CHAPTER 5

CONCLUSION

In MANET, the network created by the mobile nodes is dynamic in nature i.e. it is not confined to a particular topology because devices are free to move independently. Since there is no centralized node for monitoring in MANET routing path needs to be found dynamically. In this project we propose a novel top-k query approach to detect multiple malicious by implementing a route reply reverse tracing technique to help in achieving the stated goal. Proposed system helps us in defending against the multiple attacks without any requirement of hardware and special detection node

TOP K QUERY PROCESSING & DETECTION OF MALICIOUS NODE BASED ON NODE GROUPING IN MANETS Page 14