{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/16889"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/16889","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Alibi framework for identifying insider jamming attacks in half-duplex wireless local area networks","abstract":"\"Recent advances in wireless communications and digital electronics have enabled rapid development of a variety of wireless network technologies, such as wireless LANs, home networks, multi-hop ad hoc networks, and sensor networks. Wireless networks, unfortunately, are vulnerable to radio jamming attacks (in short, ``jamming attacks'') due to the open and shared nature of wireless medium. In a jamming attack, an attacker injects a high level of noise into the wireless system which significantly reduces the signal-to-noise ratio (SINR) and reducing the probability of successful message receptions. Even though the spread spectrum technologies have raised the bar for the jamming defenses, they cannot deal with insider jammers who launch the stealthy and intelligent jamming attacks from compromised nodes. To cope with such dangerous insider jammers, the first and most important step is to identify them. In this dissertation, we consider the problem of identifying the insider jammers. Our approach to this problem is unique: we exploit the half-duplex nature of the attackers. Specifically, a half-duplex jammer has the following characteristics: - It cannot send on two different channels simultaneously due to a non-negligible channel switching time. - It cannot receive on two different channels simultaneously due to a non-negligible channel switching time. - It cannot send and receive on a channel simultaneously due to a non-negligible transmit-to-receive switching time. Therefore, when a compromised node jams, it cannot either send or receive any other packets. More importantly, if an honest node is observed doing a send or receive action at the same time of the jammed packet, it can arguably prove that it cannot be the cause of the jammed packet. In other words, the honest node obtains an \"\"alibi\"\". Alibi is \"\"a form of defense whereby a defendant attempts to prove that he or she was elsewhere when the crime in question was committed\"\". In the context of jamming attacks, an alibi for a node is a proof showing that an honest node could not commit a jamming action at a specific time because it was witnessed doing a legitimate action at the same time. We focus on exploring the alibi framework in dealing with insider jammers. We study various properties of the framework including detection accuracy, detection time, network availability and necessary conditions for the alibi framework to work. We also investigate different designs of the alibi framework such as sending-based alibis and receiving-based alibis and study their strengths and weaknesses. We evaluate the alibi framework by the analysis, simulations and MICAz experiments. To the best of our knowledge, the alibi framework is the first framework exploiting the half-duplex nature of the nodes to identify insider attackers.\"","abstract_html":"&quot;Recent advances in wireless communications and digital electronics have enabled rapid development of a variety of wireless network technologies, such as wireless LANs, home networks, multi-hop ad hoc networks, and sensor networks. Wireless networks, unfortunately, are vulnerable to radio jamming attacks (in short, ``jamming attacks&#x27;&#x27;) due to the open and shared nature of wireless medium. In a jamming attack, an attacker injects a high level of noise into the wireless system which significantly reduces the signal-to-noise ratio (SINR) and reducing the probability of successful message receptions. Even though the spread spectrum technologies have raised the bar for the jamming defenses, they cannot deal with insider jammers who launch the stealthy and intelligent jamming attacks from compromised nodes. To cope with such dangerous insider jammers, the first and most important step is to identify them. In this dissertation, we consider the problem of identifying the insider jammers. Our approach to this problem is unique: we exploit the half-duplex nature of the attackers. Specifically, a half-duplex jammer has the following characteristics: - It cannot send on two different channels simultaneously due to a non-negligible channel switching time. - It cannot receive on two different channels simultaneously due to a non-negligible channel switching time. - It cannot send and receive on a channel simultaneously due to a non-negligible transmit-to-receive switching time. Therefore, when a compromised node jams, it cannot either send or receive any other packets. More importantly, if an honest node is observed doing a send or receive action at the same time of the jammed packet, it can arguably prove that it cannot be the cause of the jammed packet. In other words, the honest node obtains an &quot;&quot;alibi&quot;&quot;. Alibi is &quot;&quot;a form of defense whereby a defendant attempts to prove that he or she was elsewhere when the crime in question was committed&quot;&quot;. In the context of jamming attacks, an alibi for a node is a proof showing that an honest node could not commit a jamming action at a specific time because it was witnessed doing a legitimate action at the same time. We focus on exploring the alibi framework in dealing with insider jammers. We study various properties of the framework including detection accuracy, detection time, network availability and necessary conditions for the alibi framework to work. We also investigate different designs of the alibi framework such as sending-based alibis and receiving-based alibis and study their strengths and weaknesses. We evaluate the alibi framework by the analysis, simulations and MICAz experiments. To the best of our knowledge, the alibi framework is the first framework exploiting the half-duplex nature of the nodes to identify insider attackers.&quot;","abstract_has_math":false,"creators":["Nguyen, Hoang V."],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Nahrstedt, Klara","Campbell, Roy H.","Vaidya, Nitin H.","Yau, David"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2010,"date_issued":"2010-08-20T18:00:55Z","date_published":"2010-08-20T18:00:55Z","updated_at":"2026-07-22T22:25:09Z","subjects":["wireless security","jamming attacks","intrusion detection systems","alibis","system-level fault diagnosis","wireless LANs"],"languages":["en"],"rights":["Copyright 2010 Hoang Nguyen"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/16889","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nahrstedt, Klara","Campbell, Roy H.","Vaidya, Nitin H.","Yau, David"]},{"key":"dc:creator","label":"Author","values":["Nguyen, Hoang V."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2010-08-20T18:00:55Z","2010-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["wireless security","jamming attacks","intrusion detection systems","alibis","system-level fault diagnosis","wireless LANs"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2010 Hoang Nguyen"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/16889"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["\"Recent advances in wireless communications and digital electronics have enabled rapid development of a variety of wireless network technologies, such as wireless LANs, home networks, multi-hop ad hoc networks, and sensor networks. Wireless networks, unfortunately, are vulnerable to radio jamming attacks (in short, ``jamming attacks'') due to the open and shared nature of wireless medium. In a jamming attack, an attacker injects a high level of noise into the wireless system which significantly reduces the signal-to-noise ratio (SINR) and reducing the probability of successful message receptions. Even though the spread spectrum technologies have raised the bar for the jamming defenses, they cannot deal with insider jammers who launch the stealthy and intelligent jamming attacks from compromised nodes. To cope with such dangerous insider jammers, the first and most important step is to identify them. In this dissertation, we consider the problem of identifying the insider jammers. Our approach to this problem is unique: we exploit the half-duplex nature of the attackers. Specifically, a half-duplex jammer has the following characteristics: - It cannot send on two different channels simultaneously due to a non-negligible channel switching time. - It cannot receive on two different channels simultaneously due to a non-negligible channel switching time. - It cannot send and receive on a channel simultaneously due to a non-negligible transmit-to-receive switching time. Therefore, when a compromised node jams, it cannot either send or receive any other packets. More importantly, if an honest node is observed doing a send or receive action at the same time of the jammed packet, it can arguably prove that it cannot be the cause of the jammed packet. In other words, the honest node obtains an \"\"alibi\"\". Alibi is \"\"a form of defense whereby a defendant attempts to prove that he or she was elsewhere when the crime in question was committed\"\". In the context of jamming attacks, an alibi for a node is a proof showing that an honest node could not commit a jamming action at a specific time because it was witnessed doing a legitimate action at the same time. We focus on exploring the alibi framework in dealing with insider jammers. We study various properties of the framework including detection accuracy, detection time, network availability and necessary conditions for the alibi framework to work. We also investigate different designs of the alibi framework such as sending-based alibis and receiving-based alibis and study their strengths and weaknesses. We evaluate the alibi framework by the analysis, simulations and MICAz experiments. To the best of our knowledge, the alibi framework is the first framework exploiting the half-duplex nature of the nodes to identify insider attackers.\"","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-07-13T14:04:24Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 hoang_nguyen.pdf: 853768 bytes, checksum: 38f046fbbfa8f47494e925a2e96c71b0 (MD5)","Made available in DSpace on 2010-08-20T18:00:55Z (GMT). No. of bitstreams: 2 hoang_nguyen.pdf: 853768 bytes, checksum: 38f046fbbfa8f47494e925a2e96c71b0 (MD5) license.txt: 4062 bytes, checksum: afcd7685e683faa3ed0c6716ddef4725 (MD5)"]},{"key":"dc:title","label":"Title","values":["Alibi framework for identifying insider jamming attacks in half-duplex wireless local area networks"]}]}],"canonical_facts":{"dc:contributor":["Nahrstedt, Klara","Campbell, Roy H.","Vaidya, Nitin H.","Yau, David"],"dc:creator":["Nguyen, Hoang V."],"dc:date":["2010-08-20T18:00:55Z","2010-08"],"dc:description":["\"Recent advances in wireless communications and digital electronics have enabled rapid development of a variety of wireless network technologies, such as wireless LANs, home networks, multi-hop ad hoc networks, and sensor networks. Wireless networks, unfortunately, are vulnerable to radio jamming attacks (in short, ``jamming attacks'') due to the open and shared nature of wireless medium. In a jamming attack, an attacker injects a high level of noise into the wireless system which significantly reduces the signal-to-noise ratio (SINR) and reducing the probability of successful message receptions. Even though the spread spectrum technologies have raised the bar for the jamming defenses, they cannot deal with insider jammers who launch the stealthy and intelligent jamming attacks from compromised nodes. To cope with such dangerous insider jammers, the first and most important step is to identify them. In this dissertation, we consider the problem of identifying the insider jammers. Our approach to this problem is unique: we exploit the half-duplex nature of the attackers. Specifically, a half-duplex jammer has the following characteristics: - It cannot send on two different channels simultaneously due to a non-negligible channel switching time. - It cannot receive on two different channels simultaneously due to a non-negligible channel switching time. - It cannot send and receive on a channel simultaneously due to a non-negligible transmit-to-receive switching time. Therefore, when a compromised node jams, it cannot either send or receive any other packets. More importantly, if an honest node is observed doing a send or receive action at the same time of the jammed packet, it can arguably prove that it cannot be the cause of the jammed packet. In other words, the honest node obtains an \"\"alibi\"\". Alibi is \"\"a form of defense whereby a defendant attempts to prove that he or she was elsewhere when the crime in question was committed\"\". In the context of jamming attacks, an alibi for a node is a proof showing that an honest node could not commit a jamming action at a specific time because it was witnessed doing a legitimate action at the same time. We focus on exploring the alibi framework in dealing with insider jammers. We study various properties of the framework including detection accuracy, detection time, network availability and necessary conditions for the alibi framework to work. We also investigate different designs of the alibi framework such as sending-based alibis and receiving-based alibis and study their strengths and weaknesses. We evaluate the alibi framework by the analysis, simulations and MICAz experiments. To the best of our knowledge, the alibi framework is the first framework exploiting the half-duplex nature of the nodes to identify insider attackers.\"","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-07-13T14:04:24Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 hoang_nguyen.pdf: 853768 bytes, checksum: 38f046fbbfa8f47494e925a2e96c71b0 (MD5)","Made available in DSpace on 2010-08-20T18:00:55Z (GMT). No. of bitstreams: 2 hoang_nguyen.pdf: 853768 bytes, checksum: 38f046fbbfa8f47494e925a2e96c71b0 (MD5) license.txt: 4062 bytes, checksum: afcd7685e683faa3ed0c6716ddef4725 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/16889"],"dc:language":["en"],"dc:rights":["Copyright 2010 Hoang Nguyen"],"dc:subject":["wireless security","jamming attacks","intrusion detection systems","alibis","system-level fault diagnosis","wireless LANs"],"dc:title":["Alibi framework for identifying insider jamming attacks in half-duplex wireless local area networks"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:09Z"}