{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T16:33:32Z","timestamp":1761323612823,"version":"3.37.0"},"reference-count":38,"publisher":"Wiley","issue":"6","license":[{"start":{"date-parts":[[2009,4,6]],"date-time":"2009-04-06T00:00:00Z","timestamp":1238976000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security Comm Networks"],"published-print":{"date-parts":[[2009,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Social network analysis (SNA), originally introduced to provide a mathematical framework for analyzing human interactions and economic relationships, has recently been successfully applied to characterizing information propagation in wireless networks. In this paper, we introduce a SNA method as a new approach to build an intrusion detection system (SN\u2010IDS) in mobile<jats:italic>ad hoc<\/jats:italic>networks. The SN\u2010IDS utilizes social relations as metrics\u2010of\u2010interest for anomaly detections, which is different from most traditional IDS approaches. The social system can capture and represent similar network statistics as those used in data mining based IDSs. To construct proper social networks, we first investigate<jats:italic>ad hoc<\/jats:italic>MAC and network layer data attributes and select relevant social feature sets; then we build up a set of socio\u2010matrices based on these features. Social analysis methods are applied to these matrices to detect suspicious activities and behaviors of mobile nodes. The detection results can be based on single or multi\u2010relation rules. Finally, we analyze the performance of this SN\u2010IDS under different simulated mobility conditions and traffic patterns. NS\u20102 simulation results show that this SN\u2010IDS system can effectively detect common attacks with high detection rates and low false alarm rates. Furthermore, it has clear advantages over the conventional association rule based data mining IDS in terms of computation and system complexity. Copyright \u00a9 2009 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/sec.108","type":"journal-article","created":{"date-parts":[[2009,4,6]],"date-time":"2009-04-06T08:40:56Z","timestamp":1239007256000},"page":"669-685","source":"Crossref","is-referenced-by-count":18,"title":["A framework for intrusion detection systems by social network analysis methods in<i>ad hoc<\/i>networks"],"prefix":"10.1002","volume":"2","author":[{"given":"Wei","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hong","family":"Man","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2009,4,6]]},"reference":[{"key":"e_1_2_1_2_2","doi-asserted-by":"publisher","DOI":"10.1038\/30918"},{"key":"e_1_2_1_3_2","doi-asserted-by":"crossref","unstructured":"UpadrashtaY VassilevaJ GrassmannW.Social networks in peer\u2010to\u2010peer systems. InHICSS'05: Proceedings of the Proceedings of the 38th Annual Hawaii International Conference on System Sciences (HICSS'05) 2005;200c\u2013200c.","DOI":"10.1109\/HICSS.2005.546"},{"key":"e_1_2_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988759"},{"key":"e_1_2_1_5_2","unstructured":"PouwelseJ GarbackiP WangJ.et al.Tribler: a social\u2010based peer\u2010to\u2010peer system. InProceedings of the 5th International P2P conference (IPTPS 2006) no. 2006\u2010002 February2006."},{"key":"e_1_2_1_6_2","doi-asserted-by":"crossref","unstructured":"MartiS GanesanP Garcia\u2010MolinaH.Dht routing using social links. InProceedings of the International P2P Conference 2004;100\u2013111.","DOI":"10.1007\/978-3-540-30183-7_10"},{"key":"e_1_2_1_7_2","doi-asserted-by":"crossref","unstructured":"BanksL YeS HuangY WuSF.Davis social links: Integrating social networks with internet routing. InProceedings of ACM SIGCOMM Workshop on Large\u2010Scale Attack Defense Kyoto Japan August2007.","DOI":"10.1145\/1352664.1352671"},{"key":"e_1_2_1_8_2","doi-asserted-by":"crossref","unstructured":"CoffmanT MarcusS.Dynamic classification of groups through social network analysis and hmms. InProceedings of the 2004 IEEE Aerospace Conference Vol. 5 Austin TX USA March2004;3197\u20133205.","DOI":"10.1109\/AERO.2004.1368125"},{"key":"e_1_2_1_9_2","doi-asserted-by":"crossref","unstructured":"CoffmanT MarcusS.Pattern classification in social network analysis: a case study. InProceedings of the 2004 IEEE Aerospace Conference Vol. 5 Austin TX USA March2004;3162\u20133175.","DOI":"10.1109\/AERO.2004.1368121"},{"key":"e_1_2_1_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10588-005-5378-z"},{"key":"e_1_2_1_11_2","doi-asserted-by":"crossref","unstructured":"BrutchP KoC.Challenges in intrusion detection for wireless ad\u2010hoc networks. InProceedings of the Workshop on Security and Assurance in Ad\u2010hoc Networks Orlando USA January2003;368\u2013373.","DOI":"10.1109\/SAINTW.2003.1210188"},{"key":"e_1_2_1_12_2","doi-asserted-by":"crossref","unstructured":"ZhangY LeeW.Intrusion detection in wireless ad\u2010hoc networks. InProceedings of the 6th Annual International Conference on Mobile Computing and Networking (MobiCom'00) August2000;275\u2013283.","DOI":"10.1145\/345910.345958"},{"key":"e_1_2_1_13_2","doi-asserted-by":"crossref","unstructured":"HuangY LeeW.A cooperative intrusion detection system for ad hoc networks. InProceedings of the 1st ACM Workshop on Security of Ad Hoc and Sensor Networks October2003;135\u2013147.","DOI":"10.1145\/986858.986877"},{"key":"e_1_2_1_14_2","doi-asserted-by":"crossref","unstructured":"FuY HeJ LiG.A distributed intrusion detection scheme for mobile ad hoc networks. InProceedings of the 31st Annual International Computer Software and Applications Conference. IEEE Computer Society 2007;75\u201380.","DOI":"10.1109\/COMPSAC.2007.18"},{"key":"e_1_2_1_15_2","unstructured":"MellP McLarnonM.Mobile agent attack resistant distributed hierarchical intrusion detection systems. InProceedings of the Second International Workshop on Recent Advances in Intrusion Detection (RAID99) Purdue USA September1999."},{"key":"e_1_2_1_16_2","unstructured":"HsuW HelmyA.On nodal encounter patterns in wireless lan traces. InThe 2nd IEEE International Workshop on Wireless Network Measurement (WiNMee) April2006;1\u201310."},{"key":"e_1_2_1_17_2","unstructured":"HuangY FanW LeeW YuPS.Cross\u2010feature analysis for detecting ad\u2010hoc routing anomalies. In23rd International Conference on Distributed Computing System (ICDCS 2003) 2003;478\u2013787."},{"key":"e_1_2_1_18_2","first-page":"338","article-title":"Detecting blackhole attack on aodv\u2010based mobile ad hoc networks by dynamic learning","volume":"5","author":"Kurosawa1 S","year":"2007","journal-title":"International Journal of Network Security"},{"key":"e_1_2_1_19_2","doi-asserted-by":"crossref","unstructured":"LiuH GuptaR.Temporal analysis of routing activity for anomaly detection in ad hoc networks. In2006 IEEE International Conference on Mobile Adhoc and Sensor Systems (MASS) 2006;505\u2013508.","DOI":"10.1109\/MOBHOC.2006.278595"},{"key":"e_1_2_1_20_2","doi-asserted-by":"crossref","unstructured":"SunB GuanY ChenJ PoochU.Detecting black\u2010hole attack in mobile ad hoc networks. In5th European Personal Mobile Communications Conference 2003;490\u2013495.","DOI":"10.1049\/cp:20030303"},{"key":"e_1_2_1_21_2","doi-asserted-by":"crossref","unstructured":"PatchaA MishraA.Collaborative security architecture for black hole attack prevention in mobile ad hoc networks. InRadio and Wireless Conference 2003. RAWCON '03. Proceedings 2003;75\u201378.","DOI":"10.1109\/RAWCON.2003.1227896"},{"key":"e_1_2_1_22_2","doi-asserted-by":"crossref","unstructured":"JamaliM AbolhassaniH.Different aspects of social network analysis. InIEEE\/WIC\/ACM International Conference on Web Intelligence 2006 (WI 2006) 2006;66\u201372.","DOI":"10.1109\/WI.2006.61"},{"key":"e_1_2_1_23_2","doi-asserted-by":"publisher","DOI":"10.2307\/3033543"},{"key":"e_1_2_1_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/0378-8733(91)90017-N"},{"key":"e_1_2_1_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0378-8733(02)00016-3"},{"key":"e_1_2_1_26_2","doi-asserted-by":"publisher","DOI":"10.1080\/0022250X.1972.9989806"},{"key":"e_1_2_1_27_2","doi-asserted-by":"crossref","unstructured":"LiuY ManH.Network vulnerability assessment using bayesian networks. InProceedings of SPIE Data Mining Intrusion Detection Information Assurance and Data Networks Security Vol. 5812 March2005;61\u201371.","DOI":"10.1117\/12.604240"},{"key":"e_1_2_1_28_2","doi-asserted-by":"crossref","unstructured":"RojasA BranchP ArmitageG.Validation of the random waypoint mobility model through a real world mobility trace. InIEEE Region 10 (TENCON 2005) 2005;1\u20136.","DOI":"10.1109\/TENCON.2005.301339"},{"key":"e_1_2_1_29_2","doi-asserted-by":"crossref","unstructured":"ChakeresID Belding\u2010RoyerEM.The utility of hello messages for determining link connectivity. InProceedings of the 5th International Symposium on Wireless Personal Multimedia Communications 2002;504\u2013508.","DOI":"10.1109\/WPMC.2002.1088225"},{"key":"e_1_2_1_30_2","unstructured":"ShinJ LeeH NaJ ParkA KimS.Gateway discovery and routing in ad hoc networks with nat\u2010based internet connectivity. InProceedings of the Vehicular Technology Conference 2004 (VTC 2004\u2010Fall) 2004 IEEE 60th Vol. 4 2004;26\u201329."},{"key":"e_1_2_1_31_2","doi-asserted-by":"crossref","unstructured":"WangH ZhangD ShinKG.Detecting syn flooding attacks. InINFOCOM 2002. Twenty\u2010First Annual Joint Conference of the IEEE Computer and Communications Societies 3 June2002;1530\u20131539.","DOI":"10.1109\/INFCOM.2002.1019404"},{"key":"e_1_2_1_32_2","unstructured":"LeeW StolfoS.Data mining approaches for intrusion detection. InProceedings of the 7th USENIX Security Symposium San Antonio TX 1998;79\u201393."},{"key":"e_1_2_1_33_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1109\/32.372146","article-title":"State transition analysis: a rule\u2010based intrusion detection approach","volume":"21","author":"Porras PA","year":"1995","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_2_1_34_2","doi-asserted-by":"publisher","DOI":"10.1023\/A:1009748302351"},{"key":"e_1_2_1_35_2","unstructured":"AgrawalR SrikantR.Fast algorithms for mining association rules. InProceedings of the 20th International Conference on Very Large Databases September1994;135\u2013147."},{"key":"e_1_2_1_36_2","doi-asserted-by":"crossref","unstructured":"AggarwalCC YuPS.Online generation of association rules. InProceedings of the International Conference on Data Engineering. IEEE Computer Society 1998;402\u2013411.","DOI":"10.1109\/ICDE.1998.655803"},{"key":"e_1_2_1_37_2","doi-asserted-by":"crossref","unstructured":"BurdickD CalimlimM GehrkeJ.Mafia: a maximal frequent itemset algorithm for transactional databases. InProceedings of the 17th International Conference on Data Engineering (ICDE). IEEE Computer Society April2001;443\u2013452.","DOI":"10.1109\/ICDE.2001.914857"},{"key":"e_1_2_1_38_2","doi-asserted-by":"crossref","unstructured":"DingerJ HartensteinH.Defending the sybil attack in p2p networks: taxonomy challenges and a proposal for self\u2010registration. InInternational Conference on Availability Reliability and Security. IEEE Computer Society 2006;756\u2013763.","DOI":"10.1109\/ARES.2006.45"},{"key":"e_1_2_1_39_2","first-page":"115","volume-title":"proceedings of the 11th Workshop on ACM SIGOPS European Workshop","author":"Singh A","year":"2004"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.108","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.108","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/sec.108","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,8]],"date-time":"2025-02-08T21:25:12Z","timestamp":1739049912000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1002\/sec.108"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,4,6]]},"references-count":38,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2009,11]]}},"alternative-id":["10.1002\/sec.108"],"URL":"https:\/\/doi.org\/10.1002\/sec.108","archive":["Portico"],"relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"type":"print","value":"1939-0114"},{"type":"electronic","value":"1939-0122"}],"subject":[],"published":{"date-parts":[[2009,4,6]]}}}