Thursday, September 26, 2019

Operations management Essay Example | Topics and Well Written Essays - 10000 words

Operations management - Essay Example which attempted to retain market leadership by focussing solely on improvement of operational effectiveness without paying adequate attention to the overall business strategy of brand positioning and other very important human resource issues as job satisfaction, aggressiveness, motivation, performance, trust and commitment. Both made the same mistake of forgetting the broader perspective and tried to tackle an economic and marketing issue in isolation. It was only natural that both the attempts ended in failure. There were several different types of issues that had to be resolved as the project developed. At one end was the difficulty in transposing the theoretical knowledge acquired from study modules to the practical context of the project. At the other end was the lack of skill in identifying broad trends that generally tend to affect business mandarins all over the world. There surely is a trend-setter like Toyota, but it requires the experience of a veteran researcher to be able to identify a new trend and forecast a phenomenon that will sweep the world in days to come even when it is in its nascent stage and is being experimented and fine tuned by the trend setter. This ability to immediately spot an idea that would shape tomorrow’s business and commerce can only be acquired through years of patient research and, quite obviously, is not visible in the current project. At this stage, it must be admitted that the in-depth graphical analysis of the operational wheel of Tesco or a thorough examination of the technology and production processes adopted by Morgan car manufacturing company helped the researcher to attain that analytical frame of mind. The extensive knowledge (albeit theoretical) about not only lean but also agile supply chains that the researcher obtained by undertaking several projects on this topic made him fully realise the necessity of the decoupling point

Wednesday, September 25, 2019

Porter's Five-Force Analysis Case Study Example | Topics and Well Written Essays - 1250 words

Porter's Five-Force Analysis - Case Study Example The first key external environmental issue in the PHARMAC case study is the importance of regulatory agencies and authorities. From the case study, three advisory committees are identified as the key regulatory factors. The Consumer Advisory Committee (CAC), the Pharmacology and Therapeutics Advisory Committee (PTAC), and the Cancer Treatment Sub Committee (CatSop) are all identifies as the key factors (Koster, Erakovic and Smith). These committees are the advisory boards to the various elements of the external environment and the decision-making organs of PHARMAC. The other key environmental factor identified is the political factor in the operations of PHARMAC. The decision that PHARMAC made; approving the nine-week trial Herceptin drug reflects the influence of vested shareholder interests in the decision-making process. The political element is particularly important for this analysis because of the vested interests of the parties. Roche industries can be identified as having som e political influence on the analysis and the decision-making process. Porter’s Five-Force Analysis An analysis of the case study can also be done using Porter’s five-force analysis, which is used to determine every facet of the organization ranging from the profitability to the competitive threat and power of the industry (Porter, 1998). The first part of the five-force analysis is the threat of new entrants into the industry, a factor that is deemed to increase the intensity of competition. From the case study, it can be concluded that there is no threat of new entrants into PHARMAC’s industry because it is a government sanctioned advisory agency. An analysis of the second element in Porter’s five-force analysis is focused on the power of suppliers, who, in this case, are identified as the drug company Roche. The case study indicates that the supplier of Herceptin had exceptional power in the market; therefore, the bargaining power was relatively high. The third factor of Potter’s five-force analysis is the bargaining power of buyers, who, in this case, are identified as the New Zealand population and the regulatory and advisory agencies. An analysis of these buyers indicate that they have relatively low power compared to the suppliers, hence the decision to fund the nine-week trial of the drug Herceptin. The threat of substitutes is also considered in the same way as the threat of new entrants. In the funding process of new drugs, the case study indicates that PHARMAC and MedSafe are the primary considerations; therefore, there is no credible threat of substitutes. The competitive rivalry within the industry, the last factor of the industry analysis, indicates that the various factions in the funding and approval industry have different bargaining powers. The drug industry is very costly; therefore, the different competitors in the industry are identified to need massive amounts of funding to succeed. The case study also i ndicates that the critical success factor in the industry is consultation and good relations between the key players in the industry. The case study reveals that PHARMAC made its decision to fund the limited trial period for Herceptin based on a cost-benefit analysis. The success of the decision-making process could have been varied if the firm had decided to perform prior consultation with the stakeholders. This can also be supported by the success of the drug in other countries and regions. The main critical success

Tuesday, September 24, 2019

Business Report to managment on online entertainment Essay

Business Report to managment on online entertainment - Essay Example The special features will include a visually rich content, streaming video linkages to various features, flash and banner advertisements, additional benefits to members as emails on entertainment related activities including alerts on mobile, briefs on stars and music icons, gossip related news to achieve an emotional link up, games, quizzes and event markers. The company logo and motif is as given below:- The company philosophy will be as indicated in its name, to provide holistic entertainment value to persons at one location that is its web site. EntertainmentYou.com will be located in Los Angeles the hub of all entertainment and gaming activity in the World. It will have a lean organization which would be cellular and networked. A large quantum of work will be outsourced. However a minimal required employee profile will have to be maintained. Thus there will be a number of departments. A privacy policy will also be declared. This is essential to build confidence of the customer that his personal data is safe with the company. Customer policy and terms of reference will be clearly stated and personnel will have to accept the terms and conditions before becoming members. There are a number of companies operating in the on line entertainment segment of e business. Some of these are subsidiaries of large entertainment corporations as Sony. These are operating multiple entertainment sites which offer a variety of audio and video services including movies, music and even dating services. Three of these organizations are being covered in the competitor survey given below as follows:- (a) Eonline.com - URL - http://www.eonline.com. (b) Abc.com - URL - http://www.abc.com/ (c) 1netcentral.com - http://www.1netcentral.com These sites have been selected based on the popularity ratings as per Google search, the range of services provided and the variety of communications, new media inputs and overall popularity. A varied profile of the content provided by each site has been attempted to enable drawing maximum inputs for planning EntertainYou.com. Each site is being covered in detail as given below. Eonline.com E! Online is an entertainment web site which caters for a large number of entertainment needs of the modern consumer. These include music and movie reviews, coverage of live events, branded merchandise for film, TV and music enthusiasts, in addition to the latest daily news and celebrity information. The site places its USP as a fun and some what irreverent tone. Its popularity is identified by the 2.5 million users that it gets. Being a subsidiary of E! Entertainment Television Inc which is a large producer and distributor of entertainment news and life style programmes, it has ready stock of information and content available from this reliable source. Over the years it has also created an archive of 16,000 news stories and has a wide range of popular columnists

Monday, September 23, 2019

Summary Essay Example | Topics and Well Written Essays - 500 words - 128

Summary - Essay Example Though this theory measure the voting activity in terms of individual cost and benefits, it supports the ideological difference that exist between those willing to and those not willing to vote. This means that voting is a choice according to the theory of voting in relation to the voting calculus. This article depicts the reasons behind peoples’ participation or lack of participation in voting activities. According to the article, voting is a choice based on the level of commitment, civic knowledge, and finance to support the process. The three mentioned factors are grouped under resources and any of these determines whether an individual is ready to vote. A person with poor civic skill sees no need of voting and tends to calculate its benefit in line with spent time. Again, a person engaging in a more beneficial activity apart from voting sees no need in the process and continues with a more beneficial activity. This is a clear indication that voting is a choice based the costs and benefits according to the information displayed in this article. This article explains the voting process as a choice propelled by self-interest. According to the given information, nobody can participate in an activity without an interest. Voting is a public activity that involves many people though only few people benefit from the entire process (Riker & Peter, 36). For instance, the candidates and their family relations tend to benefit largely from the voting process and this explains self-interest and the level of benefit as a motivating factor. Apart from self interest, some people vote to save a magnitude without considering their interests. Voting without self-interest is a choice as explained in this article. This makes it difficult to determine whether voting is a choice or a fundamental activity. Social Identity, Political participation, and Altruism are choices that determine the voting

Sunday, September 22, 2019

Case Study on a Day Care Essay Example for Free

Case Study on a Day Care Essay When couples are engaging in family planning, there are several things that they have to take into consideration. One such thing is the care of the child or children when it is time for them to return to work. A common option over the years has been that of the day care or child care center. Parents today are realizing the importance of daycare centers in their children’s development. They are looking for daycare centers that not only will take care of their child while they are away but also will provide quality, real-life learning opportunities and experiences. These learning opportunities will ensure that children are prepared not only for their academic life in school but also for real life situations outside the daycare center and their own homes. There are five basic categories of day cares: Child care centers, educational day care, family day care, non-profit day care and subsidized day care. A child care center is a large day-care provider and is often franchised under a brand name. They often have extensive facilities, including swimming pools and large playgrounds. They also provide day care for multiple ages divided into smaller groups by age. Educational day cares are intended to provide children with pre-school learning and skills to prepare her for kindergarten or elementary school. They strive to provide children with rounded spiritual, physical, mental and emotional support to prepare them for lifes challenges. A family day care is provided in the care-givers home, usually with the providers children present. They provide a familiar and comfortable setting for your child. A family day care often is smaller than other types of day care. Non-profit day cares are run by non-profit organizations, such as churches or synagogues. They sometimes include religious schooling and are often more affordable than other types of day care because of their non-profit status. Subsidized day care programs are those that provide financial assistance either through the federal or state government or an employer. The day care visited by group five, was an educational daycare. The daycare caters to children between three (3) months and three (3) years old. At the beginning of September, there were a total of forty (40) children. Currently, there are twenty-six (26) children there. Space and Equipment The day care is clean and sanitary. There is no garbage lying around, floors are clean as they are constantly mopped when messes are made. The kitchen is large enough to facilitate the free movement when 2-3 persons are in there making food preparations. It is also away from the areas where diapers are changed and away from the bathroom. It is clear that great consideration was taken in regards to inclement weather, as the space in the day care is large enough to separate sleeping children from playing children and those who are learning. The area is large enough for everyone to play when they are unable to go outside even though the tables where they have their meals are there. There are five smoke detectors throughout the building, a fire aid kit and a fire extinguisher that are strategically places. Standard childproofing techniques are utilized, (covered outlets, safety gates, door latches). The center is secure, having a buzzer that is working and therefore, strangers are not able to just walk in from the streets. The building is properly lit and ventilated and doors are placed strategically as well to facilitate emergency exit if necessary. There is short term parking space at the front for parents and guardians who come to drop off and pick up their children. Caregivers’ Credentials/Qualifications Because the caregivers are expected to create a safe and stimulating environment for the children to develop in, it is important that the staff get formal training that will equip them with the tools necessary to do so. All the members of staff are qualified. The qualifications held are varied. There are members of staff who have Level 1 and 2 Certificates in Early Childhood Care and Development from HEART Trust NTA. Other qualification held by staff is a Certificate in Practical Nursing and Heart care and a Diploma in Early Childhood Teacher Education. Programme Activities At this stage of the child’s development, it is important to have activities that engage the children’s minds and develop skills that will be needed in further learning. At the day care, there is a structured schedule that includes plenty of time for physical activity, quiet time (including daily reading sessions for groups and individuals), group activities, individual activities, meals, snacks, and free time. The activities cover the duration of time that the children are at the day care from the moment of arrival to the time of departure. The physical activities come in varied forms including music movement (dance) and play time- outdoor play and free play. Free play is for the children to do whatever they feel like doing, whether it is engaging in imaginative play with their little friends or by themselves, playing with toys, or looking through their picture books. Outdoors, there is a slide, a swing, a monkey bar and some tires for the children to crawl through. Group activities include some aspects of the physical activities and story time, as well as their varied creative, manipulative activities. Such creative/manipulative activities include finger painting, drawing, and making things out of clay dough. This is done with the assistance of the staff. A lot of the stories are made up based on a series of pictures that are taped to the walls of the daycare. Caregivers also engage the children in picture games. The children form a ring and are shown pictures that they are to identify. Those who correctly identify the pictures get an extra treat at meal time. They are also taught nursery rhymes such as â€Å"hey diddle diddle†, and â€Å"itsy bitsy spider† and the alphabet song. There are designated times for snacks, and other meals. They do not allow the children to eat right throughout the day but encourage the habit of eating at intervals. There is also designated naptime and quiet time for the children. The activities are very appropriate as they are in keeping with Piaget’s theory of cognitive development. In the sensorimotor stage of cognitive development, which is the first stage, Piaget stresses the importance of discovery through a child’s active interaction with the environment. Between birth and age two (2), children discover the world using their senses and motor activity because they are limited by their inability to use language or symbols at this stage. Therefore, the hands on activities that they are engaged in, helps to enhance cognitive development at this stage. Teacher-child Relationships According to Erikson’s psychosocial theory of development, trust is identified as the first major developmental task of early childhood, and is established in childrens first relationship with their caregivers, parents and teachers. Trust is the first pre-requisite for effective learning. It encourages a sense of well-being and emotional security in young children, creating a solid foundation for future learning from the dynamic experiences of childhood. Without the support of early trust relationships with caring adults, children are ill-equipped to take the kinds of risk essential to the learning process. Trust develops when children come to anticipate positive experiences in the child care settings. If trust is to develop, children need sensitive and perceptive caregivers that understand childrens needs and consistently offer tender, responsive care. Having received formal training for the purpose of taking care of the children, they have an understanding of the importance of their interactions with the children and therefore treat the children accordingly. It is evident that the children trust their caregivers as they affectionately refer to them as â€Å"Auntie† and warm smile light up their tiny faces whenever they see the members of staff walk through the door. The staff plays with the children during their playtime. There is prompt responsiveness to the cries or outbursts of the children and reassurance is given when the infant is crying, except in cases when the child is throwing a tantrum. In such instances, the infant is spoken to firmly but gently. The ratio of teacher to child is 1: 6. However, the caretakers try to share their attentions evenly among the children. They tend to group the children together when they are interacting with them so that none is left out. There were demonstrations of positive reinforcement from the caregivers. When a child did not like what was prepared for them to eat, he or she was coaxed into eating by the use of various methods, one of which was to pretend that the spoonful of food was an airplane loaded with niceties. The child was praised when he or she would chew the food and swallow it. The caregiver would also reward the child with the option of having their juice before the water if the food was eaten. A sense of autonomy is identified as the second major developmental task of early childhood and is developed when a child is allowed to practice newly acquired physical skills. At the daycare, the children are encouraged to do things for themselves. There are toddlers who prefer to feed themselves, even though they make a bit of a mess when they do. Nonetheless, they are allowed to do so. They are encouraged to pick up after themselves and therefore run around picking up toys when they are done playing. During outdoor play, the older and stronger children are allowed to climb the monkey bars by themselves with the ‘Auntie’ hovering close by to give assistance if it is needed. Recommendations A good day care is one that has a good reputation. No one will want to send their child/children to a daycare that has a bad track record. Established ground rules and policies are important and this is something a good day care has. These rules and policies should include what to do when a child gets sick, or has an accident while at the daycare, schedule pick up times (even though there should be some amount of flexibility with this), safety policies, etcetera. A good day care has a stimulating curriculum that is age appropriate. As these are the formative of a child’s life, activities should be geared at setting a foundation of later learning. The day care should have a license that is current. This is an indication that the day care is in legal operation. Qualified staff is also important. Parents want to know that when they drop their children off at the day care, they are in good hands. The facilities should be clean and safe as well. The day care of study can be considered to be a good one. However, there are a few things that could be done to improve the facility. The acquisition of more qualified staff is something that should be looked into. Even though the caregivers try to pay attention to all the children in their care, it can be taxing for one staff member to have to oversee six children at once, especially during play time. There is a need for more toys for the children, especially building blocks. There is presently a toy drive going on to help with the endeavor of procuring more toys. In doing so, they can look into getting another slide as the tiny one that is there cannot suffice for all the children that want to use it during outdoor play. They need to also look into getting straps or bars put on the swing as there are children who have a habit of getting in and out of the swing while it is in flight. This can be very harmful to them. The monkey bar is also a cause of concern as it is very dangerous, especially for the smaller children. The spaces between each bar are too wide and therefore adjustments may have to be made by putting plastic or wooden bars in between each space to reduce the width that the children will have to climb on. There is a gate at the end of one of the driveways that is too far from the ground and so the ball continues to go under the gate when the children play in the driveway. They need to lower the gate or put something to block the opening so that the ball does not run onto the road. Closing Remarks Members of group five (5) can conclude that the visit to the day care was a productive one. The time spent with the children was thoroughly enjoyed as there was more than mere observation. The day care is a great one and should become better if the things in the afore mentioned recommendations are taken into consideration. Group five would recommend this day care to parents and guardians seeking one as they take into consideration the holistic development of the children.

Saturday, September 21, 2019

To what extent are the poems Nothings changed and Half-caste a message of protest Essay Example for Free

To what extent are the poems Nothings changed and Half-caste a message of protest Essay The two poems, Nothings changed by Tatamkhulu Afrika and Half-caste by John Agard, both deal with issues of race. Nothings changed describes the return to district six after the apartheid in South Africa it presents a voice angry that nothing has changed since the apartheid has been abolished, and that racial segregation still exists. Half-caste also communicates a protest against racial prejudice. It questions the use of the term half-caste and promotes more open views. The discontent behind both messages is clear in their tones. From the start Afrika sets a bitter and angry mood, the hot, white, inwards turning anger of my eyes the use of how deeply resentful he is about what is going on. Also the alliteration of the strong t consonant enhances the frustrated quality of this phrase. On the other hand Half-caste challenges the reader with a mocking phrase Excuse me standing on one leg Im half-caste. This appears to set up a more relaxed atmosphere in first three lines. The poet makes this more assertive with his use of imperatives such as excuse and explain. Throughout the poem he continues to play with the term half caste but the light atmosphere is soon over ridden by the seriousness of the message. Nothings changed is written in six main stanzas which draw attention to the harsh reality of district six. Interestingly there is a mini stanza of two lines no sign says it is but we know where we belong. this could show the racial segregation enforced and illustrates that although it is not official everybody accepts the unwritten rule. Afrika uses the power of three and the skin and the soft and the hot to demonstrate how complete and overwhelming the anger is. Also use of the refrain like phrases no board says it is and no sign says it is continue to emphasise how embedded the segregation is in society. The structure in Half caste is less obvious although it has strong implications. For example the unequal line lengths so spiteful deem dont want de sun pass/ ah rass suggest an odd untidiness and imbalance. As in nothings changed Agard uses refrain to reinforce an idea, explain yuself/ what yu mean. Although here is is more aggressive and upfront. It is repeated as he demands for an answer. There is a flow to the poem created by enjambment with no punctuation. This could reflect the release of anger. The forward slashes add pauses ? is a half-caste weather/ well in dat case which keep the reader aware of the theme of standing up against society. Both poets continue to develop the themes through rhyme and rhythm. In Nothings changed there is half rhyme, for example trees and cuisine. This could symbolise inequality and a sense of uprising against what society imposes. The rhythm is heavy and strong with hard consonant sounds like trodden and gatepost this gives a feeling of oppression. Also there is enjambment, which is shown when the poet says seeding grasses thrust/ beaded seeds/ into trouser cuffs this suggests urgency to release anger it is building up to the last line, nothings changed the short sentence ends the flow and implies defeat as the protest is replaced by acceptance that the separation still stands. Similarly the rhyme in Half-caste is random which continues the theme. The main images highlighted by rhyme such as mix a black key with a white key is a half-caste symphony. The rhythm is uneven which again emphasises the concept of half. The interesting use of colloquial language provides lots of focus on the sounds of words for example yu, de or dem which makes the rhythm more confident and direct. In nothings changed the poet begins with monosyllabic language. The first line is small round hard stone click which echoes the sound of walking on gravel this sensory language draws in the reader to the message. He uses words showing oppression like trodden on, crunched, and crushed this conveys the aggressive nature of district 6. Afrika also uses lots of heat associated words like flaring, hot white and burn. These immediately portray a build up of anger. He uses pronouns such as I press my nose making it a more personal account which engages the reader with the personal emotions. On another level he could be expressing the voice of black people against discrimination. Similarly Agard uses pronouns he engages the audience by saying yu which is directing the poem to a wide audience. He also uses colloquial language like wha, yu and on dem cloud this is Jamaican slang which sets up a background and displays his pride to be from that culture. His repeated use of the term half-caste reminds us of the taboo of the term inflicting guilt upon the reader. The clever use of half links all the imagery listening to yu wid de keen half of mih ear. This is all leading up to the last line when he challenges the reader to accept him as a whole person. Afrika uses subtle imagery like tall purple flowering amiable weeds The word weeds suggests inferiority but a struggling to stand tall against segregation. He uses personification to describe the whites only inn it squats shows how unwanted the white people are, because they impose on the black people. A strong metaphor clear panes is like a physical representation of the social barrier. It lets the wealth of the white people be seen. This is emphasised by the contrast of images created. Linen falls, the single rose are compared to bunny chows and plastic tables. Here a clear gap of living standard is shown. I think the most important image in the poem is leaving a small mean O of small mean mouth which describes the circular mark of breath on the window. This shape will disappear, and metaphorically describes how his voice of protest is lost within him. The imagery that Agard uses imagery is based around these of mix and half. Opposites like black and white and light and shadow shows two extremes which in people should be accepted as equals. He also says things like half of mih ear , half of mih eye and half-hand these are unrealistic concepts which is mocking the term half-caste. He uses a metaphor of Tchaikovsky writing a symphony and Picasso mixing colours. The use of an artist and a composer gives out a message universally. Also using art and music, pleasant things, shows how wrong and unpleasant using the term half-caste is. Finally, the change in imagery at the end of the poem shows Agards encouragement of open mindedness. He uses whole and tomorrow which suggest in the future the prejudice can change. Overall both poems show a protest although I think half-caste is defiant outwards protest that chalenges the reader with clever imagery and language. Nothings changed seems to show protest and anger held within or inwards turning anger. It also shows frustration of accepting the harsh life of being an inferior in South Africa.

Friday, September 20, 2019

Mobile Ad Hoc Network Intrusion Detection System (IDS)

Mobile Ad Hoc Network Intrusion Detection System (IDS) Chapter 1 1. Introduction Mobile ad hoc networks (MANETs) and wireless sensor networks (WSNs) are relatively new communication paradigms. MANETs do not require expensive base stations or wired infrastructure. Nodes within radio range of each other can communicate directly over wireless links, and those that are far apart use other nodes as relays. Each host in a MANET also acts as a router as routes are mostly multichip. The lack of fixed infrastructure and centralized authority makes a MANET suitable for a broad range of applications in both military and civilian environments. For example, a MANET could be deployed quickly for military communications in the battlefield. A MANET also could be deployed quickly in scenarios such as a meeting room, a city transportation wireless network, for fire fighting, and so on. To form such a cooperative and self configurable network, every mobile host should be a friendly node and willing to relay messages for others. In the original design of a MANET, global trustworthiness in nodes within the whole network is a fundamental security assumption. Recent progress in wireless communications and micro electro mechanical systems (MEMS) technology has made it feasible to build miniature wireless sensor nodes that integrate sensing, data processing, and communicating capabilities. These miniature wireless sensor nodes can be extremely small, as tiny as a cubic centimeter. Compared with conventional computers, the low-cost, battery-powered, sensor nodes have a limited energy supply, stringent processing and communications capabilities, and memory is scarce. The design and implementation of relevant services for WSNs must keep these limitations in mind. Based on the collaborative efforts of a large number of sensor nodes, WSNs have become good candidates to provide economically viable solutions for a wide range of applications, such as environmental monitoring, scientific data collection, health monitoring, and military operations. Despite the wide variety of potential applications, MANETs and WSNs often are deployed in adverse or even hostile environments. Therefore, they cannot be readily deployed without first addressing security challenges. Due to the features of an open medium, the low degree of physical security of mobile nodes, a dynamic topology, a limited power supply, and the absence of a central management point, MANETs are more vulnerable to malicious attacks than traditional wired networks are. In WSNs, the lack of physical security combined with unattended operations make sensor nodes prone to a high risk of being captured and compromised, making WSNs vulnerable to a variety of attacks. A mobile ad hoc network (MANET) is a self-configuring network that is formed automatically by a collection of mobile nodes without the help of a fixed infrastructure or centralized management. Each node is equipped with a wireless transmitter and receiver, which allow it to communicate with other nodes in its radio communication range. In order for a node to forward a packet to a node that is out of its radio range, the cooperation of other nodes in the network is needed; this is known as multi-hop communication. Therefore, each node must act as both a host and a router at the same time. The network topology frequently changes due to the mobility of mobile nodes as they move within, move into, or move out of the network. A MANET with the characteristics described above was originally developed for military purposes, as nodes are scattered across a battlefield and there is no infrastructure to help them form a network. In recent years, MANETs have been developing rapidly and are increasingly being used in many applications, ranging from military to civilian and commercial uses, since setting up such networks can be done without the help of any infrastructure or interaction with a human. Some examples are: search-and-rescue missions, data collection, and virtual classrooms and conferences where laptops, PDA or other mobile devices share wireless medium and communicate to each other. As MANETs become widely used, the security issue has become one of the primary concerns. For example, most of the routing protocols proposed for MANETs assume that every node in the network is cooperative and not malicious [1]. Therefore, only one compromised node can cause the failure of the entire network. There are both passive and active attacks in MANETs. For passive at tacks, packets containing secret information might be eavesdropped, which violates confidentiality. Active attacks, including injecting packets to invalid destinations into the network, deleting packets, modifying the contents of packets, and impersonating other nodes violate availability, integrity, authentication, and non-repudiation. Proactive approaches such as cryptography and authentication were first brought into consideration, and many techniques have been proposed and implemented. However, these applications are not sufficient. If we have the ability to detect the attack once it comes into the network, we can stop it from doing any damage to the system or any data. Here is where the intrusion detection system comes in. Intrusion detection can be defined as a process of monitoring activities in a system, which can be a computer or network system. The mechanism by which this is achieved is called an intrusion detection system (IDS). An IDS collects activity information and then analyzes it to determine whether there are any activities that violate the security rules. Once AN ID determines that an unusual activity or an activity that is known to be an attack occurs, it then generates an alarm to alert the security administrator. In addition, IDS can also initiate a proper response to the malicious activity. Although there are several intrusion detection techniques developed for wired networks today, they are not suitable for wireless networks due to the differences in their characteristics. Therefore, those techniques must be modified or new techniques must be developed to make intrusion detection work effectively in MANETs. In this paper, we classify the architectures for IDS in MANETs, each of which is suitable for different network infrastructures. Current intrusion detection systems corresponding to those architectures are reviewed and compared. Chapter 2 Background 2.1 Intrusion Detection System (IDS) Many historical events have shown that intrusion prevention techniques alone, such as encryption and authentication, which are usually a first line of defense, are not sufficient. As the system become more complex, there are also more weaknesses, which lead to more security problems. Intrusion detection can be used as a second wall of defense to protect the network from such problems. If the intrusion is detected, a response can be initiated to prevent or minimize damage to the system. To make intrusion detection systems work, basic assumptions are made. The first assumption is that user and program activities are observable. The second assumption, which is more important, is that normal and intrusive activities must have distinct behaviors, as intrusion detection must capture and analyze system activity to determine if the system is under attack. Intrusion detection can be classified based on audit data as either host- based or network-based. A network-based IDS captures and analyzes packets from network tra ±c while a host-based IDS uses operating system or application logs in its analysis. Based on detection techniques, IDS can also be classified into three categories as follows [2]. Anomaly detection systems: The normal profiles (or normal behaviors) of users are kept in the system. The system compares the captured data with these profiles, and then treats any activity that deviates from the baseline as a possible intrusion by informing system administrators or initializing a proper response. Misuse detection systems: The system keeps patterns (or signatures) of known attacks and uses them to compare with the captured data. Any matched pattern is treated as an intrusion. Like a virus detection system, it cannot detect new kinds of attacks. Specification-based detection: The system defines a set of constraints that describe the correct operation of a program or protocol. Then, it monitors the execution of the program with respect to the defined constraints. 2.2 Intrusion Detection in MANETs Many intrusion detection systems have been proposed in traditional wired networks, where all track must go through switches, routers, or gateways. Hence, IDS can be added to and implemented in these devices easily [17, 18]. On the other hand, MANETs do not have such devices. Moreover, the medium is wide open, so both legitimate and malicious users can access it. Furthermore, there is no clear separation between normal and unusual activities in a mobile environment. Since nodes can move arbitrarily, false routing information could be from a compromised node or a node that has outdated information. Thus, the current IDS techniques on wired networks cannot be applied directly to MANETs. Many intrusion detection systems have been proposed to suit the characteristics of MANETs, some of which will be discussed in the next sections. 2.3 Architectures for IDS in MANETs The network infrastructures that MANETs can be configured to are either at or multi-layer, depending on the applications. Therefore, the optimal IDS architecture for a MANET may depend on the network infrastructure itself [9]. In an network infrastructure, all nodes are considered equal, thus it may be suitable for applications such as virtual classrooms or conferences. On the contrary, some nodes are considered different in the multi-layered network infrastructure. Nodes may be partitioned into clusters with one cluster head for each cluster. To communicate within the cluster, nodes can communicate directly. However, communication across the clusters must be done through the cluster head. This infrastructure might be well suited for military applications. 2.3.1 Stand-alone Intrusion Detection Systems In this architecture, an intrusion detection system is run on each node independently to determine intrusions. Every decision made is based only on information collected at its own node, since there is no cooperation among nodes in the network. Therefore, no data is exchanged. Besides, nodes in the same network do not know anything about the situation on other nodes in the network as no alert information is passed. Although this architecture is not elective due to its limitations, it may be suitable in a network where not all nodes are capable of running IDS or have IDS installed. This architecture is also more suitable for an network infrastructure than for multi-layered network infrastructure. Since information on each individual node might not be enough to detect intrusions, this architecture has not been chosen in most of the IDS for MANETs. 2.3.2 Distributed and Cooperative Intrusion Detection Systems Since the nature of MANETs is distributed and requires cooperation of other nodes, Zhang and Lee [1] have proposed that the intrusion detection and response system in MANETs should also be both distributed and cooperative as shown in Figure 1. Every node participates in intrusion detection and response by having an IDS agent running on them. An IDS agent is responsible for detecting and collecting local events and data to identify possible intrusions, as well as initiating a response independently. However, neighboring IDS agents cooperatively participate in global intrusion detection actions when the evidence is inconclusive. Similarly to stand-alone IDS architecture, this architecture is more suitable for a network infrastructure, not multi-layered one. 2.3.3 Hierarchical Intrusion Detection Systems Hierarchical IDS architectures extend the distributed and cooperative IDS architectures and have been proposed for multi-layered network infrastructures where the network is divided into clusters. Clusterheads of each cluster usually have more functionality than other members in the clusters, for example routing packets across clusters. Thus, these cluster heads, in some sense, act as control points which are similar to switches, routers, or gateways in wired networks. The same concept of multi-layering is applied to intrusion detection systems where hierarchical IDS architecture is proposed. Each IDS agent is run on every member node and is responsible locally for its node, i.e., monitoring and deciding on locally detected intrusions. A clusterhead is responsible locally for its node as well as globally for its cluster, e.g. monitoring network packets and initiating a global response when network intrusion is detected. 2.3.4 Mobile Agent for Intrusion Detection Systems A concept of mobile agents has been used in several techniques for intrusion detection systems in MANETs. Due to its ability to move through the large network, each mobile agent is assigned to perform only one specific task, and then one or more mobile agents are distributed into each node in the network. This allows the distribution of the intrusion detection tasks. There are several advantages for using mobile agents [2]. Some functions are not assigned to every node; thus, it helps to reduce the consumption of power, which is scarce in mobile ad hoc networks. It also provides fault tolerance such that if the network is partitioned or some agents are destroyed, they are still able to work. Moreover, they are scalable in large and varied system environments, as mobile agents tend to be independent of platform architectures. However, these systems would require a secure module where mobile agents can be stationed to. Additionally, mobile agents must be able to protect themselves from the secure modules on remote hosts as well. Mobile-agent-based IDS can be considered as a distributed and cooper ative intrusion detection technique as described in Section 3.2. Moreover, some techniques also use mobile agents combined with hierarchical IDS, for example, what will be described in Section 4.3. 2.4 Sample Intrusion Detection Systems for MANETs Since the IDS for traditional wired systems are not well-suited to MANETs, many researchers have proposed several IDS especially for MANETs, which some of them will be reviewed in this section. 2.4.1 Distributed and Cooperative IDS As described in Section 3.2, Zhang and Lee also proposed the model for distributed and cooperative IDS as shown in Figure 2 [1]. The model for an IDS agent is structured into six modules. The local data collection module collects real-time audit data, which includes system and user activities within its radio range. This collected data will be analyzed by the local detection engine module for evidence of anomalies. If an anomaly is detected with strong evidence, the IDS agent can determine independently that the system is under attack and initiate a response through the local response module (i.e., alerting the local user) or the global response module (i.e., deciding on an action), depending on the type of intrusion, the type of network protocols and applications, and the certainty of the evidence. If an anomaly is detected with weak or inconclusive evidence, the IDS agent can request the cooperation of neighboring IDS agents through a cooperative detection engine module, which communicates to other agents through a secure communication module. 2.4.2 Local Intrusion Detection System (LIDS) Albers et al. [3] proposed a distributed and collaborative architecture of IDS by using mobile agents. A Local Intrusion Detection System (LIDS) is implemented on every node for local concern, which can be extended for global concern by cooperating with other LIDS. Two types of data are exchanged among LIDS: security data and intrusion alerts. In order to analyze the possible intrusion, data must be obtained from what the LIDS detect, along with additional information from other nodes. Other LIDS might be run on different operating systems or use data from different activities such as system, application, or network activities; therefore, the format of this raw data might be different, which makes it hard for LIDS to analyze. However, such difficulties can be solved by using SNMP (Simple Network Management Protocol) data located in MIBs (Management Information Base) as an audit data source. Such a data source not only eliminates those difficulties, but also reduces the in-Figure 3: L IDS Architecture in A Mobile Node [3] crease in using additional resources to collect audit data if an SNMP agent is already run on each node. To obtain additional information from other nodes, the authors proposed mobile agents to be used to transport SNMP requests to other nodes. In another words, to distribute the intrusion detection tasks. The idea differs from traditional SNMP in that the traditional approach transfers data to the requesting node for computation while this approach brings the code to the data on the requested node. This is initiated due to untrustworthiness of UDP messages practiced in SNMP and the active topology of MANETs. As a result, the amount of exchanged data is tremendously reduced. Each mobile agent can be assigned a specific task which will be achieved in an autonomous and asynchronous fashion without any help from its LIDS. The LIDS architecture is shown in Figure 3, which consists of  ² Communication Framework: To facilitate for both internal and external communication with a LIDS. Local LIDS Agent: To be responsible for local intrusion detection and local response. Also, it reacts to intrusion alerts sent from other nodes to protect itself against this intrusion. Local MIB Agent: To provide a means of collecting MIB variables for either mobile agents or the Local LIDS Agent. Local MIB Agent acts as an interface with SNMP agent, if SNMP exists and runs on the node, or with a tailor-made agent developed specifically to allow up- dates and retrievals of the MIB variables used by intrusion detection, if none exists. Mobile Agents (MA): They are distributed from its LID to collect and process data on other nodes. The results from their evaluation are then either sent back to their LIDS or sent to another node for further investigation. Mobile Agents Place: To provide a security control to mobile agents. For the methodology of detection, Local IDS Agent can use either anomaly or misuse detection. However, the combination of two mechanisms will offer the better model. Once the local intrusion is detected, the LIDS initiate a response and inform the other nodes in the network. Upon receiving an alert, the LIDS can protect itself against the intrusion. 2.4.3 Distributed Intrusion Detection System Using Multiple Sensors Kachirski and Guha [4] proposed a multi-sensor intrusion detection system based on mobile agent technology. The system can be divided into three main modules, each of which represents a mobile agent with certain func- tionality: monitoring, decision-making or initiating a response. By separate in functional tasks into categories and assigning each task to a different agent, the workload is distributed which is suitable for the characteristics of MANETs. In addition, the hierarchical structure of agents is also developed in this intrusion detection system as shown in Figure 4. Monitoring agent: Two functions are carried out at this class of agent: network monitoring and host monitoring. A host-based monitor agent hosting system-level sensors and user-activity sensors is run on every node to monitor within the node, while a monitor agent with a network monitoring sensor is run only on some selected nodes to monitor at packet-level to capture packets going through the network within its radio ranges. Action agent: Every node also hosts this action agent. Since every node hosts a host-based monitoring agent, it can determine if there is any suspicious or unusual activities on the host node based on anomaly detection. When there is strong evidence supporting the anomaly detected, this action agent can initiate a response, such as terminating the process or blocking a user from the network. Decision agent: The decision agent is run only on certain nodes, mostly those nodes that run network monitoring agents. These nodes collect all packets within its radio range and analyze them to determine whether the network is under attack. Moreover, from the previous paragraph, if the local detection agent cannot make a decision on its own due to insufficient evidence, its local detection agent reports to this decision agent in order to investigate further. This is done by using packet-monitoring results that comes from the network-monitoring sensor that is running locally. If the decision agent concludes that the node is malicious, the action module of the agent running on that node as described above will carry out the response. The network is logically divided into clusters with a single cluster head for each cluster. This clusterhead will monitor the packets within the cluster and only packets whose originators are in the same cluster are captured and investigated. This means that the network monitoring agent (with network monitoring sensor) and the decision agent are run on the cluster head. In this mechanism, the decision agent performs the decision-making based on its own collected information from its network-monitoring sensor; thus, other nodes have no influence on its decision. This way, spooffing attacks and false accusations can be prevented. 2.4.4 Dynamic Hierarchical Intrusion Detection Architecture Since nodes move arbitrarily across the network, a static hierarchy is not suitable for such dynamic network topology. Sterne et al. [16] proposed a dynamic intrusion detection hierarchy that is potentially scalable to large networks by using clustering like those in Section 4.3 and 5.5. However, it can be structured in more than two levels as shown in Figure 5. Nodes labeled 1 are the first level clusterheads while nodes labeled 2 are the second level clusterheads and so on. Members of the first level of the cluster are called leaf nodes. Every node has the responsibilities of monitoring (by accumulating counts and statistics), logging, analyzing (i.e., attack signature matching or checking on packet headers and payloads), responding to intrusions detected if there is enough evidence, and alerting or reporting to cluster heads. Clues treads, in addition, must also perform: Data fusion/integration and data reduction: Clusterheads aggregate and correlate reports from members of the cluster and data of their own. Data reduction may be involved to avoid conflicting data, bogus data and overlapping reports. Besides, cluster heads may send the requests to their children for additional information in order to correlate reports correctly. Intrusion detection computations: Since different attacks require different sets of detected data, data on a single node might not be able to detect the attack, e.g., DDoS attack, and thus clusterheads also analyze the consolidated data before passing to upper levels. Security Management: The uppermost levels of the hierarchy have the authority and responsibility for managing the detection and response capabilities of the clusters and cluster heads below them. They may send the signatures update, or directives and policies to alter the configurations for intrusion detection and response. These update and directives will flow from the top of the hierarchy to the bottom. To form the hierarchical structure, every node uses clustering, which is typically used in MANETs to construct routes, to self-organize into local neighborhoods (first level clusters) and then select neighborhood representatives (cluster heads). These representatives then use clustering to organize themselves into the second level and select the representatives. This process continues until all nodes in the network are part of the hierarchy. The authors also suggested criteria on selecting cluster heads. Some of these criteria are: Connectivity: the number of nodes within one hop Proximity: members should be within one hop of its cluster head Resistance to compromise (hardening): the probability that the node will not be compromised. This is very important for the upper level cluster heads. Processing power, storage capacity, energy remaining, bandwidth cape abilities Additionally, this proposed architecture does not rely solely on promiscuous node monitoring like many proposed architectures, due to its unreliability as described in. Therefore, this architecture also supports direct periodic reporting where packet counts and statistics are sent to monitoring nodes periodically. 2.4.5 Zone-Based Intrusion Detection System (ZBIDS) Sun et al. [24] has proposed an anomaly-based two-level no overlapping Zone-Based Intrusion Detection System (ZBIDS). By dividing the network in Figure 6 into nonoverlapping zones (zone A to zone me), nodes can be categorized into two types: the intrazone node and the interzone node (or a gateway node). Considering only zone E, node 5, 9, 10 and 11 are intrazone nodes, while node 2, 3, 6, and 8 are interzone nodes which have physical connections to nodes in other zones. The formation and maintenance of zones requires each node to know its own physical location and to map its location to a zone map, which requires prior design setup. Each node has an IDS agent run on it which the model of the agent is shown in Figure 7. Similar to an IDS agent proposed by Zhang and Lee (Figure 2), the data collection module and the detection engine are re-sponsible for collecting local audit data (for instance, system call activities, and system log les) and analyzing collected data for any sign of intrusion respectively. In addition, there may be more than one for each of these modules which allows collecting data from various sources and using different detection techniques to improve the detection performance. The local aggregation and correlation (LACE) module is responsible for combining the results of these local detection engines and generating alerts if any abnormal behavior is detected. These alerts are broadcasted to other nodes within the same zone. However, for the global aggregation and correlation (GACE), its functionality depends on the type of the node. As described in Figure 7, if the node is an intrazone node, it only sends the generated alerts to the interzone nodes. Whereas, if the node is an interzone node, it receives alerts from other intrazone nodes, aggregates and correlates those alerts with its own alerts, and then generates alarms. Moreover, the GACE also cooperates with the GACEs of the neighboring interzone nodes to have more accurate information to detect the intrusion. Lastly, the intrusion response module is responsible for handling the alarms generated from the GACE. The local aggregation and correlation Algorithm used in ZBIDS is based on a local Markov chain anomaly detection. IDS agent rust creates a normal profile by constructing a Markov chain from the routing cache. A valid change in the routing cache can be characterized by the Markov chain detection model with probabilities, otherwise, its considered abnormal, and the alert will be generated. For the global aggregation and correlation algorithm, its based on information provided in the received alerts containing the type, the time, and the source of the attacks. 2.5 Intrusion Detection Techniques for Node Cooperation in MANETs Since there is no infrastructure in mobile ad hoc networks, each node must rely on other nodes for cooperation in routing and forwarding packets to the destination. Intermediate nodes might agree to forward the packets but actually drop or modify them because they are misbehaving. The simulations in [5] show that only a few misbehaving nodes can degrade the performance of the entire system. There are several proposed techniques and protocols to detect such misbehavior in order to avoid those nodes, and some schemes also propose punishment as well [6, 7]. 2.5.1 Watchdog and Pathrater Two techniques were proposed by Marti, Giuli, and Baker [5], watchdog and pathrater, to be added on top of the standard routing protocol in ad hoc networks. The standard is Dynamic Source Routing protocol (DSR) [8]. A watchdog identifies the misbehaving nodes by eavesdropping on the transmission of the next hop. A pathrater then helps to find the routes that do not contain those nodes. In DSR, the routing information is defined at the source node. This routing information is passed together with the message through intermediate nodes until it reaches the destination. Therefore, each intermediate node in the path should know who the next hop node is. In addition, listening to the next hops transmission is possible because of the characteristic of wireless networks if node A is within range of node B, A can overhear communication to and from B. Figure 8 shows how the watchdog works. Assume that node S wants to send a packet to node D, which there exists a path from S to D through nodes A, B, and C. Consider now that A has already received a packet from S destined to D. The packet contains a message and routing information. When A forwards this packet to B, A also keeps a copy of the packet in its buffer. Then, it promiscuously listens to the transmission of B to make sure that B forwards to C. If the packet overheard from B (represented by a dashed line) matches that stored in the buffer, it means that B really forwards to the next hop (represented as a solid line). It then removes the packet from the buffer. However, if theres no matched packet after a certain time, the watchdog increments the failures counter for node B. If this counter exceeds the threshold, A concludes that B is misbehaving and reports to the source node S. Path rater performs the calculation of the path metric for each path. By keeping the rating of every node in the network that it knows, the path metric can be calculated by combining the node rating together with link re- liability, which is collected from past experience. Obtaining the path metric for all available paths, the pathrater can choose the path with the highest metric. In addition, if there is no such link reliability information, the path metric enables the pathrater to select the shortest path too. As a result, paths containing misbehaving nodes will be avoided. From the result of the simulation, the system with these two techniques is quite effective for choosing paths to avoid misbehaving nodes. However, those misbehaving nodes are not punished. In contrast, they even benefit from the network. Therefore, misbehaving nodes are encouraged to continue their behaviors. Chapter 3 3. Literature survey 3.1 Introduction The rapid proliferation of wireless networks and mobile computing applications has changed the landscape of network security. The nature of mobility creates new vulnerabilities that do not exist in a fixed wired network, and yet many of the proven security measures turn out to be ineffective. Therefore, the traditional way of protecting networks with firewalls and encryption software is no longer sufficient. We need to develop new architecture and mechanisms to protect the wireless networks and mobile computing applications. The implication of mobile computing on network security research can be further demonstrated by the follow case. Recently (Summer 2001) an Internet worm called Code Red has spread rapidly to infect many of the Windows-based server machines. To prevent this type of worm attacks from spreading into intranets, many. This paper Mobile Ad Hoc Network Intrusion Detection System (IDS) Mobile Ad Hoc Network Intrusion Detection System (IDS) Chapter 1 1. Introduction Mobile ad hoc networks (MANETs) and wireless sensor networks (WSNs) are relatively new communication paradigms. MANETs do not require expensive base stations or wired infrastructure. Nodes within radio range of each other can communicate directly over wireless links, and those that are far apart use other nodes as relays. Each host in a MANET also acts as a router as routes are mostly multichip. The lack of fixed infrastructure and centralized authority makes a MANET suitable for a broad range of applications in both military and civilian environments. For example, a MANET could be deployed quickly for military communications in the battlefield. A MANET also could be deployed quickly in scenarios such as a meeting room, a city transportation wireless network, for fire fighting, and so on. To form such a cooperative and self configurable network, every mobile host should be a friendly node and willing to relay messages for others. In the original design of a MANET, global trustworthiness in nodes within the whole network is a fundamental security assumption. Recent progress in wireless communications and micro electro mechanical systems (MEMS) technology has made it feasible to build miniature wireless sensor nodes that integrate sensing, data processing, and communicating capabilities. These miniature wireless sensor nodes can be extremely small, as tiny as a cubic centimeter. Compared with conventional computers, the low-cost, battery-powered, sensor nodes have a limited energy supply, stringent processing and communications capabilities, and memory is scarce. The design and implementation of relevant services for WSNs must keep these limitations in mind. Based on the collaborative efforts of a large number of sensor nodes, WSNs have become good candidates to provide economically viable solutions for a wide range of applications, such as environmental monitoring, scientific data collection, health monitoring, and military operations. Despite the wide variety of potential applications, MANETs and WSNs often are deployed in adverse or even hostile environments. Therefore, they cannot be readily deployed without first addressing security challenges. Due to the features of an open medium, the low degree of physical security of mobile nodes, a dynamic topology, a limited power supply, and the absence of a central management point, MANETs are more vulnerable to malicious attacks than traditional wired networks are. In WSNs, the lack of physical security combined with unattended operations make sensor nodes prone to a high risk of being captured and compromised, making WSNs vulnerable to a variety of attacks. A mobile ad hoc network (MANET) is a self-configuring network that is formed automatically by a collection of mobile nodes without the help of a fixed infrastructure or centralized management. Each node is equipped with a wireless transmitter and receiver, which allow it to communicate with other nodes in its radio communication range. In order for a node to forward a packet to a node that is out of its radio range, the cooperation of other nodes in the network is needed; this is known as multi-hop communication. Therefore, each node must act as both a host and a router at the same time. The network topology frequently changes due to the mobility of mobile nodes as they move within, move into, or move out of the network. A MANET with the characteristics described above was originally developed for military purposes, as nodes are scattered across a battlefield and there is no infrastructure to help them form a network. In recent years, MANETs have been developing rapidly and are increasingly being used in many applications, ranging from military to civilian and commercial uses, since setting up such networks can be done without the help of any infrastructure or interaction with a human. Some examples are: search-and-rescue missions, data collection, and virtual classrooms and conferences where laptops, PDA or other mobile devices share wireless medium and communicate to each other. As MANETs become widely used, the security issue has become one of the primary concerns. For example, most of the routing protocols proposed for MANETs assume that every node in the network is cooperative and not malicious [1]. Therefore, only one compromised node can cause the failure of the entire network. There are both passive and active attacks in MANETs. For passive at tacks, packets containing secret information might be eavesdropped, which violates confidentiality. Active attacks, including injecting packets to invalid destinations into the network, deleting packets, modifying the contents of packets, and impersonating other nodes violate availability, integrity, authentication, and non-repudiation. Proactive approaches such as cryptography and authentication were first brought into consideration, and many techniques have been proposed and implemented. However, these applications are not sufficient. If we have the ability to detect the attack once it comes into the network, we can stop it from doing any damage to the system or any data. Here is where the intrusion detection system comes in. Intrusion detection can be defined as a process of monitoring activities in a system, which can be a computer or network system. The mechanism by which this is achieved is called an intrusion detection system (IDS). An IDS collects activity information and then analyzes it to determine whether there are any activities that violate the security rules. Once AN ID determines that an unusual activity or an activity that is known to be an attack occurs, it then generates an alarm to alert the security administrator. In addition, IDS can also initiate a proper response to the malicious activity. Although there are several intrusion detection techniques developed for wired networks today, they are not suitable for wireless networks due to the differences in their characteristics. Therefore, those techniques must be modified or new techniques must be developed to make intrusion detection work effectively in MANETs. In this paper, we classify the architectures for IDS in MANETs, each of which is suitable for different network infrastructures. Current intrusion detection systems corresponding to those architectures are reviewed and compared. Chapter 2 Background 2.1 Intrusion Detection System (IDS) Many historical events have shown that intrusion prevention techniques alone, such as encryption and authentication, which are usually a first line of defense, are not sufficient. As the system become more complex, there are also more weaknesses, which lead to more security problems. Intrusion detection can be used as a second wall of defense to protect the network from such problems. If the intrusion is detected, a response can be initiated to prevent or minimize damage to the system. To make intrusion detection systems work, basic assumptions are made. The first assumption is that user and program activities are observable. The second assumption, which is more important, is that normal and intrusive activities must have distinct behaviors, as intrusion detection must capture and analyze system activity to determine if the system is under attack. Intrusion detection can be classified based on audit data as either host- based or network-based. A network-based IDS captures and analyzes packets from network tra ±c while a host-based IDS uses operating system or application logs in its analysis. Based on detection techniques, IDS can also be classified into three categories as follows [2]. Anomaly detection systems: The normal profiles (or normal behaviors) of users are kept in the system. The system compares the captured data with these profiles, and then treats any activity that deviates from the baseline as a possible intrusion by informing system administrators or initializing a proper response. Misuse detection systems: The system keeps patterns (or signatures) of known attacks and uses them to compare with the captured data. Any matched pattern is treated as an intrusion. Like a virus detection system, it cannot detect new kinds of attacks. Specification-based detection: The system defines a set of constraints that describe the correct operation of a program or protocol. Then, it monitors the execution of the program with respect to the defined constraints. 2.2 Intrusion Detection in MANETs Many intrusion detection systems have been proposed in traditional wired networks, where all track must go through switches, routers, or gateways. Hence, IDS can be added to and implemented in these devices easily [17, 18]. On the other hand, MANETs do not have such devices. Moreover, the medium is wide open, so both legitimate and malicious users can access it. Furthermore, there is no clear separation between normal and unusual activities in a mobile environment. Since nodes can move arbitrarily, false routing information could be from a compromised node or a node that has outdated information. Thus, the current IDS techniques on wired networks cannot be applied directly to MANETs. Many intrusion detection systems have been proposed to suit the characteristics of MANETs, some of which will be discussed in the next sections. 2.3 Architectures for IDS in MANETs The network infrastructures that MANETs can be configured to are either at or multi-layer, depending on the applications. Therefore, the optimal IDS architecture for a MANET may depend on the network infrastructure itself [9]. In an network infrastructure, all nodes are considered equal, thus it may be suitable for applications such as virtual classrooms or conferences. On the contrary, some nodes are considered different in the multi-layered network infrastructure. Nodes may be partitioned into clusters with one cluster head for each cluster. To communicate within the cluster, nodes can communicate directly. However, communication across the clusters must be done through the cluster head. This infrastructure might be well suited for military applications. 2.3.1 Stand-alone Intrusion Detection Systems In this architecture, an intrusion detection system is run on each node independently to determine intrusions. Every decision made is based only on information collected at its own node, since there is no cooperation among nodes in the network. Therefore, no data is exchanged. Besides, nodes in the same network do not know anything about the situation on other nodes in the network as no alert information is passed. Although this architecture is not elective due to its limitations, it may be suitable in a network where not all nodes are capable of running IDS or have IDS installed. This architecture is also more suitable for an network infrastructure than for multi-layered network infrastructure. Since information on each individual node might not be enough to detect intrusions, this architecture has not been chosen in most of the IDS for MANETs. 2.3.2 Distributed and Cooperative Intrusion Detection Systems Since the nature of MANETs is distributed and requires cooperation of other nodes, Zhang and Lee [1] have proposed that the intrusion detection and response system in MANETs should also be both distributed and cooperative as shown in Figure 1. Every node participates in intrusion detection and response by having an IDS agent running on them. An IDS agent is responsible for detecting and collecting local events and data to identify possible intrusions, as well as initiating a response independently. However, neighboring IDS agents cooperatively participate in global intrusion detection actions when the evidence is inconclusive. Similarly to stand-alone IDS architecture, this architecture is more suitable for a network infrastructure, not multi-layered one. 2.3.3 Hierarchical Intrusion Detection Systems Hierarchical IDS architectures extend the distributed and cooperative IDS architectures and have been proposed for multi-layered network infrastructures where the network is divided into clusters. Clusterheads of each cluster usually have more functionality than other members in the clusters, for example routing packets across clusters. Thus, these cluster heads, in some sense, act as control points which are similar to switches, routers, or gateways in wired networks. The same concept of multi-layering is applied to intrusion detection systems where hierarchical IDS architecture is proposed. Each IDS agent is run on every member node and is responsible locally for its node, i.e., monitoring and deciding on locally detected intrusions. A clusterhead is responsible locally for its node as well as globally for its cluster, e.g. monitoring network packets and initiating a global response when network intrusion is detected. 2.3.4 Mobile Agent for Intrusion Detection Systems A concept of mobile agents has been used in several techniques for intrusion detection systems in MANETs. Due to its ability to move through the large network, each mobile agent is assigned to perform only one specific task, and then one or more mobile agents are distributed into each node in the network. This allows the distribution of the intrusion detection tasks. There are several advantages for using mobile agents [2]. Some functions are not assigned to every node; thus, it helps to reduce the consumption of power, which is scarce in mobile ad hoc networks. It also provides fault tolerance such that if the network is partitioned or some agents are destroyed, they are still able to work. Moreover, they are scalable in large and varied system environments, as mobile agents tend to be independent of platform architectures. However, these systems would require a secure module where mobile agents can be stationed to. Additionally, mobile agents must be able to protect themselves from the secure modules on remote hosts as well. Mobile-agent-based IDS can be considered as a distributed and cooper ative intrusion detection technique as described in Section 3.2. Moreover, some techniques also use mobile agents combined with hierarchical IDS, for example, what will be described in Section 4.3. 2.4 Sample Intrusion Detection Systems for MANETs Since the IDS for traditional wired systems are not well-suited to MANETs, many researchers have proposed several IDS especially for MANETs, which some of them will be reviewed in this section. 2.4.1 Distributed and Cooperative IDS As described in Section 3.2, Zhang and Lee also proposed the model for distributed and cooperative IDS as shown in Figure 2 [1]. The model for an IDS agent is structured into six modules. The local data collection module collects real-time audit data, which includes system and user activities within its radio range. This collected data will be analyzed by the local detection engine module for evidence of anomalies. If an anomaly is detected with strong evidence, the IDS agent can determine independently that the system is under attack and initiate a response through the local response module (i.e., alerting the local user) or the global response module (i.e., deciding on an action), depending on the type of intrusion, the type of network protocols and applications, and the certainty of the evidence. If an anomaly is detected with weak or inconclusive evidence, the IDS agent can request the cooperation of neighboring IDS agents through a cooperative detection engine module, which communicates to other agents through a secure communication module. 2.4.2 Local Intrusion Detection System (LIDS) Albers et al. [3] proposed a distributed and collaborative architecture of IDS by using mobile agents. A Local Intrusion Detection System (LIDS) is implemented on every node for local concern, which can be extended for global concern by cooperating with other LIDS. Two types of data are exchanged among LIDS: security data and intrusion alerts. In order to analyze the possible intrusion, data must be obtained from what the LIDS detect, along with additional information from other nodes. Other LIDS might be run on different operating systems or use data from different activities such as system, application, or network activities; therefore, the format of this raw data might be different, which makes it hard for LIDS to analyze. However, such difficulties can be solved by using SNMP (Simple Network Management Protocol) data located in MIBs (Management Information Base) as an audit data source. Such a data source not only eliminates those difficulties, but also reduces the in-Figure 3: L IDS Architecture in A Mobile Node [3] crease in using additional resources to collect audit data if an SNMP agent is already run on each node. To obtain additional information from other nodes, the authors proposed mobile agents to be used to transport SNMP requests to other nodes. In another words, to distribute the intrusion detection tasks. The idea differs from traditional SNMP in that the traditional approach transfers data to the requesting node for computation while this approach brings the code to the data on the requested node. This is initiated due to untrustworthiness of UDP messages practiced in SNMP and the active topology of MANETs. As a result, the amount of exchanged data is tremendously reduced. Each mobile agent can be assigned a specific task which will be achieved in an autonomous and asynchronous fashion without any help from its LIDS. The LIDS architecture is shown in Figure 3, which consists of  ² Communication Framework: To facilitate for both internal and external communication with a LIDS. Local LIDS Agent: To be responsible for local intrusion detection and local response. Also, it reacts to intrusion alerts sent from other nodes to protect itself against this intrusion. Local MIB Agent: To provide a means of collecting MIB variables for either mobile agents or the Local LIDS Agent. Local MIB Agent acts as an interface with SNMP agent, if SNMP exists and runs on the node, or with a tailor-made agent developed specifically to allow up- dates and retrievals of the MIB variables used by intrusion detection, if none exists. Mobile Agents (MA): They are distributed from its LID to collect and process data on other nodes. The results from their evaluation are then either sent back to their LIDS or sent to another node for further investigation. Mobile Agents Place: To provide a security control to mobile agents. For the methodology of detection, Local IDS Agent can use either anomaly or misuse detection. However, the combination of two mechanisms will offer the better model. Once the local intrusion is detected, the LIDS initiate a response and inform the other nodes in the network. Upon receiving an alert, the LIDS can protect itself against the intrusion. 2.4.3 Distributed Intrusion Detection System Using Multiple Sensors Kachirski and Guha [4] proposed a multi-sensor intrusion detection system based on mobile agent technology. The system can be divided into three main modules, each of which represents a mobile agent with certain func- tionality: monitoring, decision-making or initiating a response. By separate in functional tasks into categories and assigning each task to a different agent, the workload is distributed which is suitable for the characteristics of MANETs. In addition, the hierarchical structure of agents is also developed in this intrusion detection system as shown in Figure 4. Monitoring agent: Two functions are carried out at this class of agent: network monitoring and host monitoring. A host-based monitor agent hosting system-level sensors and user-activity sensors is run on every node to monitor within the node, while a monitor agent with a network monitoring sensor is run only on some selected nodes to monitor at packet-level to capture packets going through the network within its radio ranges. Action agent: Every node also hosts this action agent. Since every node hosts a host-based monitoring agent, it can determine if there is any suspicious or unusual activities on the host node based on anomaly detection. When there is strong evidence supporting the anomaly detected, this action agent can initiate a response, such as terminating the process or blocking a user from the network. Decision agent: The decision agent is run only on certain nodes, mostly those nodes that run network monitoring agents. These nodes collect all packets within its radio range and analyze them to determine whether the network is under attack. Moreover, from the previous paragraph, if the local detection agent cannot make a decision on its own due to insufficient evidence, its local detection agent reports to this decision agent in order to investigate further. This is done by using packet-monitoring results that comes from the network-monitoring sensor that is running locally. If the decision agent concludes that the node is malicious, the action module of the agent running on that node as described above will carry out the response. The network is logically divided into clusters with a single cluster head for each cluster. This clusterhead will monitor the packets within the cluster and only packets whose originators are in the same cluster are captured and investigated. This means that the network monitoring agent (with network monitoring sensor) and the decision agent are run on the cluster head. In this mechanism, the decision agent performs the decision-making based on its own collected information from its network-monitoring sensor; thus, other nodes have no influence on its decision. This way, spooffing attacks and false accusations can be prevented. 2.4.4 Dynamic Hierarchical Intrusion Detection Architecture Since nodes move arbitrarily across the network, a static hierarchy is not suitable for such dynamic network topology. Sterne et al. [16] proposed a dynamic intrusion detection hierarchy that is potentially scalable to large networks by using clustering like those in Section 4.3 and 5.5. However, it can be structured in more than two levels as shown in Figure 5. Nodes labeled 1 are the first level clusterheads while nodes labeled 2 are the second level clusterheads and so on. Members of the first level of the cluster are called leaf nodes. Every node has the responsibilities of monitoring (by accumulating counts and statistics), logging, analyzing (i.e., attack signature matching or checking on packet headers and payloads), responding to intrusions detected if there is enough evidence, and alerting or reporting to cluster heads. Clues treads, in addition, must also perform: Data fusion/integration and data reduction: Clusterheads aggregate and correlate reports from members of the cluster and data of their own. Data reduction may be involved to avoid conflicting data, bogus data and overlapping reports. Besides, cluster heads may send the requests to their children for additional information in order to correlate reports correctly. Intrusion detection computations: Since different attacks require different sets of detected data, data on a single node might not be able to detect the attack, e.g., DDoS attack, and thus clusterheads also analyze the consolidated data before passing to upper levels. Security Management: The uppermost levels of the hierarchy have the authority and responsibility for managing the detection and response capabilities of the clusters and cluster heads below them. They may send the signatures update, or directives and policies to alter the configurations for intrusion detection and response. These update and directives will flow from the top of the hierarchy to the bottom. To form the hierarchical structure, every node uses clustering, which is typically used in MANETs to construct routes, to self-organize into local neighborhoods (first level clusters) and then select neighborhood representatives (cluster heads). These representatives then use clustering to organize themselves into the second level and select the representatives. This process continues until all nodes in the network are part of the hierarchy. The authors also suggested criteria on selecting cluster heads. Some of these criteria are: Connectivity: the number of nodes within one hop Proximity: members should be within one hop of its cluster head Resistance to compromise (hardening): the probability that the node will not be compromised. This is very important for the upper level cluster heads. Processing power, storage capacity, energy remaining, bandwidth cape abilities Additionally, this proposed architecture does not rely solely on promiscuous node monitoring like many proposed architectures, due to its unreliability as described in. Therefore, this architecture also supports direct periodic reporting where packet counts and statistics are sent to monitoring nodes periodically. 2.4.5 Zone-Based Intrusion Detection System (ZBIDS) Sun et al. [24] has proposed an anomaly-based two-level no overlapping Zone-Based Intrusion Detection System (ZBIDS). By dividing the network in Figure 6 into nonoverlapping zones (zone A to zone me), nodes can be categorized into two types: the intrazone node and the interzone node (or a gateway node). Considering only zone E, node 5, 9, 10 and 11 are intrazone nodes, while node 2, 3, 6, and 8 are interzone nodes which have physical connections to nodes in other zones. The formation and maintenance of zones requires each node to know its own physical location and to map its location to a zone map, which requires prior design setup. Each node has an IDS agent run on it which the model of the agent is shown in Figure 7. Similar to an IDS agent proposed by Zhang and Lee (Figure 2), the data collection module and the detection engine are re-sponsible for collecting local audit data (for instance, system call activities, and system log les) and analyzing collected data for any sign of intrusion respectively. In addition, there may be more than one for each of these modules which allows collecting data from various sources and using different detection techniques to improve the detection performance. The local aggregation and correlation (LACE) module is responsible for combining the results of these local detection engines and generating alerts if any abnormal behavior is detected. These alerts are broadcasted to other nodes within the same zone. However, for the global aggregation and correlation (GACE), its functionality depends on the type of the node. As described in Figure 7, if the node is an intrazone node, it only sends the generated alerts to the interzone nodes. Whereas, if the node is an interzone node, it receives alerts from other intrazone nodes, aggregates and correlates those alerts with its own alerts, and then generates alarms. Moreover, the GACE also cooperates with the GACEs of the neighboring interzone nodes to have more accurate information to detect the intrusion. Lastly, the intrusion response module is responsible for handling the alarms generated from the GACE. The local aggregation and correlation Algorithm used in ZBIDS is based on a local Markov chain anomaly detection. IDS agent rust creates a normal profile by constructing a Markov chain from the routing cache. A valid change in the routing cache can be characterized by the Markov chain detection model with probabilities, otherwise, its considered abnormal, and the alert will be generated. For the global aggregation and correlation algorithm, its based on information provided in the received alerts containing the type, the time, and the source of the attacks. 2.5 Intrusion Detection Techniques for Node Cooperation in MANETs Since there is no infrastructure in mobile ad hoc networks, each node must rely on other nodes for cooperation in routing and forwarding packets to the destination. Intermediate nodes might agree to forward the packets but actually drop or modify them because they are misbehaving. The simulations in [5] show that only a few misbehaving nodes can degrade the performance of the entire system. There are several proposed techniques and protocols to detect such misbehavior in order to avoid those nodes, and some schemes also propose punishment as well [6, 7]. 2.5.1 Watchdog and Pathrater Two techniques were proposed by Marti, Giuli, and Baker [5], watchdog and pathrater, to be added on top of the standard routing protocol in ad hoc networks. The standard is Dynamic Source Routing protocol (DSR) [8]. A watchdog identifies the misbehaving nodes by eavesdropping on the transmission of the next hop. A pathrater then helps to find the routes that do not contain those nodes. In DSR, the routing information is defined at the source node. This routing information is passed together with the message through intermediate nodes until it reaches the destination. Therefore, each intermediate node in the path should know who the next hop node is. In addition, listening to the next hops transmission is possible because of the characteristic of wireless networks if node A is within range of node B, A can overhear communication to and from B. Figure 8 shows how the watchdog works. Assume that node S wants to send a packet to node D, which there exists a path from S to D through nodes A, B, and C. Consider now that A has already received a packet from S destined to D. The packet contains a message and routing information. When A forwards this packet to B, A also keeps a copy of the packet in its buffer. Then, it promiscuously listens to the transmission of B to make sure that B forwards to C. If the packet overheard from B (represented by a dashed line) matches that stored in the buffer, it means that B really forwards to the next hop (represented as a solid line). It then removes the packet from the buffer. However, if theres no matched packet after a certain time, the watchdog increments the failures counter for node B. If this counter exceeds the threshold, A concludes that B is misbehaving and reports to the source node S. Path rater performs the calculation of the path metric for each path. By keeping the rating of every node in the network that it knows, the path metric can be calculated by combining the node rating together with link re- liability, which is collected from past experience. Obtaining the path metric for all available paths, the pathrater can choose the path with the highest metric. In addition, if there is no such link reliability information, the path metric enables the pathrater to select the shortest path too. As a result, paths containing misbehaving nodes will be avoided. From the result of the simulation, the system with these two techniques is quite effective for choosing paths to avoid misbehaving nodes. However, those misbehaving nodes are not punished. In contrast, they even benefit from the network. Therefore, misbehaving nodes are encouraged to continue their behaviors. Chapter 3 3. Literature survey 3.1 Introduction The rapid proliferation of wireless networks and mobile computing applications has changed the landscape of network security. The nature of mobility creates new vulnerabilities that do not exist in a fixed wired network, and yet many of the proven security measures turn out to be ineffective. Therefore, the traditional way of protecting networks with firewalls and encryption software is no longer sufficient. We need to develop new architecture and mechanisms to protect the wireless networks and mobile computing applications. The implication of mobile computing on network security research can be further demonstrated by the follow case. Recently (Summer 2001) an Internet worm called Code Red has spread rapidly to infect many of the Windows-based server machines. To prevent this type of worm attacks from spreading into intranets, many. This paper