Abstract
Wireless Sensor Networks (WSNs) have been extensively used in various applications such as environmental monitoring, industrial monitoring, agriculture, green house monitoring, structural monitoring, passive localization, tracking and battlefield surveillance. Sensor nodes in these applications are required to sense and process the physical conditions like temperature, pressure, humidity, rainfall, fog, etc. and route the data to a predefined base station or a sink node. In most of these applications, sensor nodes are deployed in public domain and they are prone to be attacked by many types of attacks where in the data confidentiality, integrity and authentication are compromised. Some times, it is difficult to correctly locate the compromised data unless we use autonomous third party that uses intelligent software techniques to safeguard our data and correctly means route it to destined party.
In this paper, we propose a Trust based Neighbor Identification in Wireless Sensor Networks (TNIWSN) using agents to identify trustworthy nodes in a network. The trusted neighbor identification is necessary for routing the data through trustworthy neighbors and avoid untrusted neighbors that are compromised by various threats. The proposed scheme operates in following phases. (1) Defining safeguard agency that consists of one static agent known as Safeguard Manager Agent (SMA) and one mobile agent known as Trusted Neighbor Agent (TNA) and a knowledge base. (2) Safeguard agency identifies trustworthy neighbor nodes using static and mobile agents by means of trust model that comprise of the probability model and Message Authentication Code (MAC) model. The probability model identifies trusted neighbors based upon the probabilities of trustworthiness of wireless channel and the trustworthiness of sensor node. MAC model encrypts the message using the two keys
Keywords
Introduction
Secured routing in WSN should focus on identifying the neighbors which are free from various types of attacks. It becomes a challenging task to identify the neighbors that are trustworthy since attackers make the nodes not only to pretend as if they are trustworthy and free of any types of attacks but also create a feeling that they are involved in avoiding any types of threats. In such a situation, traditional mechanisms of security schemes may not be sufficient and thus we need intelligent schemes to overcome such challenges. Software agent technology provides the promising secured routing mechanism where in autonomous agents are involved in identifying all types of security threats and secured routes in WSNs with the help of neighbor nodes that are trustworthy and the routes may be created using such neighbors.
Fundamental components to decide upon a neighbor as trustworthy are wireless channel connecting the neighbor node and computation activity of a neighbor node. An adversary may attack wireless channel in several forms such as jamming, radio interference, tampering, collision, repeated requests, sybil attack, sink hole attack, black hole attack, worm hole attack, hello flood attack, de-synchronization attack, reprogram attack, etc. [8]. Computation activity of a sensor node plays significant role to perform various activities such as sensing and interpreting different physical parameters, processing and storing the sensed data, aggregating and communicating the data to neighbor nodes, etc. [13]. Attacks that affect the computation activity of sensor nodes may be classified into two categories: (1) black out attacks and (2) mis-behavioral attacks. A black out attack is one in which the node is not able to perform any type of activity such as sensing the event, processing the data, communication with neighbors, etc. A node mis-behavioral attack is one in which the node exhibits normal behavior but performs abnormal computations and this type of attack is difficult to identify. For example, suppose a node is required to sense the current weather condition (such as temperature, pressure, humidity, etc.) and report the same to its neighbor. In such a situation, the mis-behaving node may correctly sense the environment; but it may alter the position of the parameters in the data field to be communicated to the neighbor. Thus, temperature, pressure, humidity will be read wrongly so that the network suffers in terms of energy spent for such communication, time required to process and transmit to the neighbor. A trusted neighbor node is one where it is free from two types of attacks listed above.
The task of securing wireless channel and computation activity of a node using traditional security mechanisms are not sufficient since such schemes do not possess intelligent techniques. Effective deployment of security mechanism needs intelligence to identify such security violations and should be able to take autonomous decisions intelligently. Since software agents are suitable to take autonomous decisions and act intelligently, we use agent technology to identify trustworthy neighbors against the two types of security violations in WSNs.
Agents are software programs activated on an agent platform of a host. Agents use their own knowledge base to achieve the specified goals without disturbing the activities of the host. They have two important properties: mandatory and orthogonal, which differentiates them from standard programs. Some of the mandatory properties are: autonomy, reactive, proactive and temporally continuous. Some of the orthogonal properties are: communicative, mobile, learning and believable. Mobile agent is an itinerant agent which contains program, data, execution state information, migrates from one host to another host in a heterogeneous network, and executes at a remote host until it completes a given task [3,15].
In this paper, we use agents that help in correctly identifying such vulnerabilities of channel conditions and sensor nodes to find trusted neighbors and avoid further complications.
Related works
Some of the related works are as follows. Authors in [10] focus on the study of security threats to the WSN that proposes a security solution using mobile agent technology. The model is based on two requirements confidentiality and integrity. To maintain confidentiality a software mobile agent based key management technique is proposed which consists of three phases initial key distribution phase, control phase, execution phase. For integrity the author proposed agent based integrity maintenance model for WSNs. The owner creates dummy offer signs with private key, encrypt with public key and then transmit. At the host it will be decrypted using public key and private key. However, the proposal does not consider authenticity of data.
A bio-inspired trust and reputation model in WSN (BTRM-WSN) is proposed in [5] which is based on Ant Colony Systems (ACS) and aims at providing trust and reputation in WSNs. Pheromone updating is carried out by ACS that includes measuring of the quality of a path, how to punish or reward a server depending on dynamic behavior of pheromone. The overhead of maintaining ACS becomes very large as the network scales up. BTRM-WSN performs multiple iterations to select secured routes and there is no assurance that all the ants launched by the client will return back in a single iteration to compare and select the best path. This leads to increase in latency and increased security threats.
The author in [17] proposes a method to defend against sink hole attacks using mobile agents. A routing algorithm with multiple constraints is proposed based on mobile agents. It uses mobile agents to collect information of all mobile sensor nodes to make every node aware of the entire network so that a valid node will not listen the cheating information from malicious or compromised node which leads to sink hole attack. One of the features of the proposed mechanism is that it does not need any encryption or decryption mechanism to detect the sink hole attack. This mechanism does not require more energy than normal routing protocols like AODV. The system proposes two algorithms. In agent navigation algorithm, the agents collect network information of visited nodes. In data routing algorithm, the global network information is used to route data packets. The problem with this proposal is that since it does not use encryption/decryption mechanisms, dealing with security violations depend on the capability of agents and if the agents are compromised, the whole purpose is lost.
The work given in [22] presents a Neighbor-based Malicious Node Detection (NMND) in WSN in which malicious nodes are modeled as faulty nodes to lead to an incorrect decisions that cannot be easily detected. Each sensor node makes a decision on the fault status of itself and its neighboring nodes based on the sensor readings. Most erroneous readings due to transient faults are corrected by filtering, while nodes with permanent faults are removed using confidence level evaluation. Each node maintains confidence levels of itself and its neighbors, indicating the track records in reporting past events. However, detecting malicious nodes based on only the readings from sensor nodes is not effective. Permanent and transient faults detected may not be due to security violations. We used this paper for comparing the results of our proposal. The motivation to compare the results with NMND is that it identifies malicious neighbor nodes and it is closely related to TNIWSN wherein trusted neighbor nodes are identified.
The authors in [12] focus on the critical role played by mobile agent (MA) for security and robustness of a WSN in addition to data fusion. The design objectives of JAID (Jamming Avoidance Itinerary Design) algorithm are as follows: (a) to calculate near-optimal routes for MAs that incrementally fuse the data as they visit the nodes and (b) in the face of jamming attacks. It modifies the itineraries of the MAs to bypass the jammed area(s) while not disrupting the efficient data dissemination from working sensors. If the number of jammed nodes is small, JAID modifies the pre-jamming scheduled itineraries to increase the algorithm’s promptness. Otherwise, JAID re-constructs the agent itineraries excluding the jammed area(s). JAID also suppresses the data taken from sensors when the associated successive readings do not vary significantly. Data suppression also occurs when sensors’ readings are identical to those of their neighboring sensors. This proposal aims only at jamming attacks and it does not consider data confidentiality, integrity and authenticity against various types of attacks.
Some of the reasons for using mobile agents in fault tolerant networks have been highlighted in [11]. Agents reduce the network load, enhance fault tolerant capability, provide personal assistance, secure brokering, distributed information retrieval, support telecommunication networks services, work-flow applications and groupware-support for the flow of information among coworkers, monitoring and notification. This work do not consider security aspects in any way. The authors in [7] propose a secured routing mechanism in sensor networks and it shows how attacks against ad hoc and peer-to-peer networks can be adapted into powerful attacks against sensor networks. It introduces two classes of attacks such as sinkhole attacks and hello flood attacks and thereby it analyzes the security of sensor network routing protocols. This work assumes that the base station as trustworthy and builds up the secured routes in the network. This assumption is unrealistic in real-life scenarios as base stations are also prone to attacks.
A security management framework has been proposed in WSN [19] that performs following tasks: processing the data from wireless sensor networks, managing the secret key distribution and renewal, detecting malicious nodes, mining the potential attack and malicious nodes. However, this work does not discuss the details of secret key generation, distribution and renewal. This framework fails in addressing how the trustworthiness of a node in WSN is assessed. The authors in [2] propose mobile agent based sensor network architecture for reducing and aggregating data (it is known as Mobile Agent based Wireless Sensor Network (MAWSN)). Agents in MAWSN perform the following functions: (1) eliminating data redundancy among sensors by application local processing at the node level, (2) eliminating spatial redundancy among closely located sensors by data aggregation at the task level, (3) reducing communication overhead by concatenating data at the combined task level. Four performance metrics such as energy consumption, average end-to-end packet delay, energy delay, packet delivery ratio have been analysed. In this work, security aspects are not considered.
Use of smartcards as a tamper resistant devices to offer security to WSN is proposed [14]. Hardware cryptographic platform includes link level communication, transport protocol description, application interface description and demands for power consumption. The authors specify that smartcards are standardized devices that offer common communication interface and can be used with cryptographic platform in accordance with the standards. This work does not ensure trustworthiness of sensor nodes and needs standards to be incorporated in smartcard devices. Secure hardware contains secret cryptographic key, which is used only for encrypting data and this key is stored in the card which cannot be read. The authors in [1] propose an Agent-based Trust and Reputation Management scheme (ATRM) for WSN that considers bandwidth and delay overheads. The objective of the scheme is to manage trust and reputation locally with minimal overhead in terms of extra messages and time delay. ATRM scheme requires that a node’s trust and reputation information to be stored respectively in the forms of t-instrument and r-certificate by the node itself. Since, nodes cannot manage and compute their own trust and reputation, ATRM requires that every node locally hold a mobile agent that is in charge of administrating the trust and reputation of its hosting node. In this sense, mobile agents provide one-to-one trust and reputation management service. The drawback of this scheme is that mobile agents carry un-encrypted messages which may be vulnerable to security threats.
The authors in [16] propose an agent-based approach that maintains the node’s current status. The detection of a node is possible through the ratings of each node. Ratings of a node are known through the ratio of packet forwarded by packets received. Ratings are also computed using the E-commerce models in which each node votes the successive node depending upon the ratio of packet forwarded by packets received. The update ratings will be determined by either Sporas formula or Molina’s formula or with a combination of both models. The proposed framework uses reputation of a node through neighboring nodes as part of trust calculation. This proposal neither addresses trust level of a node nor provides the details of how security violations are arrested.
Coordinated sensing of data in distributed environment has been discussed in [6] through directed diffusion technique that is based upon data centric approach. Since the nodes are application aware, it enables diffusion to achieve energy savings by selecting better paths through data aggregation. The work evaluates the use of directed diffusion for remote surveillance sensor network analytically and experimentally. The quantitative and qualitative methods of error propagation are proposed in [9] to analyze possible error propagation scenarios based on different topologies, error types and probability distributions. Various types of structures studied are regular structure, random structure, small structure and scale free structures. The complex structures help to model naturally occurring events, such as social networks using graph-theoretic approach. The survey of trust and reputation models in wireless communication have been discussed in [23]. The state of the art in the application of trust models in the fields of mobile ad hoc networks, wireless sensor networks and cognitive radio networks. Communication traffic dynamics and patterns in WSNs has been discussed in [20]. The communication traffic in WSNs for surveillance and target tracking are investigated. Different types of communication traffic discussed in this work include data traffic, routing discovery traffic, link layer feedback and hello message, etc. with a main focus on data traffic.
Contribution of the paper
The proposed agent based trusted neighbor identification scheme in WSN is motivated by observing several drawbacks of existing trustworthy neighbor identification schemes that are severely suffering from vulnerabilities of wireless channel and sensor node. In this paper, we propose an agent based trusted neighbor identification in WSN that uses probabilities of the channel and node along with the MAC model for their trustworthiness. Our previous work [4] discussed trusted neighbor identification in WSN using only MAC model. The work was not supported by probability model and also lacked detailed formulation of components of the scheme. This paper provides an extension to the work by providing detailed functioning of the scheme, examples and simulation based performance analysis.
Our contribution in the paper are as follows: (1) defining trust model that comprises probability model and MAC model to find security violations of wireless channel and sensor node, (2) employing agents to carry the encrypted message to the neighbor nodes, (3) using agents to identify trustworthy neighbors, (4) engage agents to dynamically update trustworthiness of neighbor nodes and (5) simulation analysis in terms of average success ratio and memory overhead and comparing our results with NMND.
Remainder of this paper is organized as follows. Section 2 explains the procedure to identify trusted neighbors using trust model. Section 3 describes agent based trusted node identification which describes the organization of agency using detailed functioning of agents. Section 4 presents simulation model and simulation procedure. Section 5 discusses the simulation results for various performance measures highlighting the benefits of using software agents. Finally, conclusions are given in Section 6.
Trusted neighbor identification
Glossary of variables and symbols
Glossary of variables and symbols
Possible threats to the sensor networks from adversaries are in terms of threats to the wireless channel and threats to sensor nodes. The wireless channel in WSN is prone to several attacks as there is no control over the packets transmitted. Wireless channel may be made more secured if the information to be transmitted on the channel is hidden by using cryptographic techniques. One of such cryptographic mechanisms is generating Message Authentication Code (MAC) and encrypting the resulting message thus providing authenticity, confidentiality and integrity. Misbehavior of a neighbor node is another major concern since it is difficult to identify whether a node is compromised. A compromised node may seem to be a normal node but the processing of data is affected and thus wrong computations yield unexpected results. To handle such type of attacks, one needs intelligent techniques wherein the affected communication and processing platforms are easily identified. We develop a trust model that is required to tackle security violations of wireless channel and sensor nodes.
Trust model consists of the probability model and MAC model. The probability model identifies trusted neighbors based upon the probabilities of trustworthiness of wireless channel and the trustworthiness of sensor node. MAC model encrypts the message using the two keys
Probability model
The probability model to identify trustworthy neighbors is described as follows. Let a sensor node has n number of neighbor nodes and let

Trusted neighbor identification using probability model
A node having its neighbors list is defined as a set
As our objective is to design a secured system using probability of trustworthy nodes, there needs to be certain value of probability threshold to decide upon the security level, above which the system is assumed to be secured. Depending upon the application requirements, we can decide the value of θ anywhere between 0 and 1. The trusted neighbor identification is given in Algorithm 1.
For example, a node X computes trustworthy neighbors list in

Trusted neighbor node selection.

MAC generation to identify trusted neighbors.
Corresponding to 7 neighbors, the probability values in
Suppose, the threshold
Thus, among 7 neighbor nodes, only 5 nodes are trustworthy (i.e., node 1, node 4, node 5, node 6 and node 7) and node 2, node 3 are not trustworthy. Further, MAC model ensures the trustworthiness among trusted neighbors identified by probability model. That means, among 5 trustworthy neighbors found by probability model, some of them may proved to be untrusted using MAC model.
The cryptographic systems are designed to perform complicated encryption and the creation of message authentication becomes challenging in spite of various attacks from adversaries. Many protocols are designed based on the assumption that the hosts posses a secret random string known as key and it is conveniently taken for granted that the entire key is kept secret from an adversary. There might be a possibility that an adversary may detect a part or entire key which is called as key exposure problem and it has significant practical interests. The keys required for obtaining MAC and encrypted message are generated by Exposure Resilient Function (ERF) [21].
The reason for using ERF for the key generation is that it provides highly randomness in the generated key such that if any part of the key is known to the adversary, it is not possible to recover the entire key. We introduce the mechanism of MAC generation using ERF and we describe how the scheme is implemented to identify the trusted neighbors in order to maintain confidentiality, authentication and integrity.
In specific, we use an adaptive k-ERF to generate a random key. k-ERF is defined as a function f for a random input seed s, such that
The process of generating MAC using k-ERF is shown in Fig. 2.
The MAC encrypted message is sent to the neighbors that are found to be trustworthy by probability model. Re-computation of MAC on neighbor nodes ensures the trustworthiness of the wireless channel and the sensor node thereby endorsing the trusted neighbors identified by the probability model.
Software agents are used to identify the trusted neighbors with the help of trust model discussed in Section 2. Trusted neighbor identification in WSN using agents comprises of two agencies: Safeguard Agency (SA) and Routing Agency (RA) and a Knowledge Base (KB) as shown in Fig. 3.
Agent packet structure and its attributes
Agent packet structure and its attributes

Secured routing agency.
SA comprises of agents and a KB. A static agent known as Safeguard Manager Agent (SMA) triggers mobile agent known as Trusted Neighbor Agent (TNA). SMA and TNA identify trusted neighbors that are free from various types of attacks. RA comprises of a static agent known as Route Manager Agent (RMA) and mobile agents known as Route Construction Agent (RCA) and Route Sustenance Agent (RSA). RMA and RCA construct secured routes from a source node to a sink node with the help of only trusted neighbors that are identified by safeguard agency. Once the secured routes are constructed, it is equally important to sustain the routes for the complete duration of data transfer. RMA and RSA perform the task of route sustainability against security violations. KB consists of various information used by the agents to identify trusted neighbors.
Trusted neighbors are identified in every node proactively, i.e., trusted neighbors are updated regularly so that the RA constructs the routes only with trusted neighbors thereby avoiding possible security violations. Trusted neighbor based routing operates in two phases: (1) identifying trusted neighbors using SA and (2) constructing secured routes using RA.
In this paper, we propose the scheme for trusted neighbor identification using SA and the scheme of routing with trusted neighbors using RA will be our future work.
The packet structure of an agent and its attributes to perform the given task of neighbor node identification is given in Table 2.
Agent class: There are two classes of agents – static agents and mobile agents. Static agents perform various tasks at the node such as monitoring the performance of the node, creating mobile nodes and deploy them for specific application, take autonomous decisions, etc. Whereas mobile agents perform the task assigned by the static agent by visiting other nodes and taking autonomous decisions at the visited node, returning the refined information to the static agent. Agent header: This field contains source address, visiting node address, lifetime of an agent, clone number, etc. Agent functions: Specific functions of agents include MAC computation, carrying keys to the visiting nodes, destroying itself either at the expiry of its lifetime or the visited node is found to be untrustworthy, etc. Agent data: It is the information needed to perform agent functions.
The details of agents and their functions are discussed in Section 3.2.2.
Identification of trusted neighbors using safeguard agency
In this section, we discuss the procedure to identify the trusted neighbors by SA. SA identifies the trusted neighbors against channel and node vulnerabilities. The structure of SA on a node willing to identify its trusted neighbors is shown in Fig. 4 which contains agents SMA, TNA, k-ERF generator and a Knowledge Base (KB). Suppose the SA in node 2 wishes to identify its trusted neighbors, the SMA triggers the mobile agent TNA to visit its neighbors and identify whether the neighbor is a trusted one.

Safeguard agency for trusted neighbor identification.

Encryption of a message by SMA
The MAC computation and encrypting the message is given in Algorithm 2. The secured message M to be communicated to the neighbor is comprised of information such as source address (
The message to be transmitted is broken into blocks
Node KB
Node KB
Neighbor node KB
The specific purpose of KB components are listed below.
Node address: It is the address of a node willing to identify its trustworthy neighbors.
θ: Probability threshold, used to differentiate trusted and untrusted neighbors.
Nonce: Used to identify the session uniquely.
A node also maintains the data related to its neighbors in Neighbor node KB. For example, the components corresponding to a neighbor 172.121.253.6, the node 172.121.253.4 maintains the following data.
Similarly, the node 172.121.253.4 maintains the data related to all its neighbors.
Safeguard Agency (comprising of SMA and TNA) is responsible for identifying trusted neighbors. The sequence of operations performed by SMA and TNA are discussed in this section.
Safeguard Manager Agent (SMA): It is a static agent in SA that gets activated whenever a node wishes to identify its trusted neighbors. The functions of SMA are as follows. (1) Creates TNA and clones number of TNA’s equal to the number of neighbor nodes. (2) TNA’s visit neighbor nodes and compute Trusted Neighbor Agent (TNA): It is a mobile agent generated by SMA. The functions of TNA are as follows. (1) Visits the neighbor node and computes
The purpose of finding trusted neighbors using the probability model is that it identifies security violations of the channel and the sensor node thereby it provides a means of first level security in finding trusted neighbors. The purpose of computing the
Simulation model
Agent based trusted neighbor selection scheme is simulated in various network scenarios to assess the performance and effectiveness of the approach. Event driven simulation is used in which the execution of various functions takes place at discrete events in a chronological sequence. Simulation environment for the proposed work consists of four models: (1) Network model, (2) Trust model, (3) Propagation model and (4) Traffic model. The models are discussed below.
Network model: A sensor network is generated in an area of Trust Model: Trust model consists of Propagation model: Free space propagation model is used with propagation constant β. Transmission range of a node is r for a one-hop distance. Traffic model: Constant bit rate model is used to transmit fixed size packets,
Simulation procedure
The proposed scheme is simulated using the following simulation inputs:
Simulation procedure involves following steps.
Generate sensor network environment: The nodes are randomly deployed in a fixed area and for a fixed topology. The results are obtained for a fixed set of simulation inputs. For stability of results, we performed several simulations and the average of all the results is considered. Agents visit the neighbor node and bring channel and node probability for their trustworthiness using probability model. Agents ensure trustworthiness of channel and node using MAC model. Compute performance parameters of the system: Performance parameters are assessed and plotted with different variables.
We created agent structures using C language and provided various capabilities to each agent through linked list structures. Both static and mobile agents are independent software modules and they have distinct set of input output operations for different set of variables along with processing code of its function. The capabilities of agents such as mobility, autonomous decisions, independence, etc. have been implemented through parameter passing among the agent modules.

Average success ratio vs. number of nodes.
The following performance parameters are assessed.
Average Success Ratio (ASR): ASR is defined as is the average of Success Ratios (SR) computed at selected number of K nodes. SR for single node in the network is defined as a ratio of number of trustworthy neighbor nodes identified by agent based scheme to the actual number of trustworthy neighbor nodes. SR at a node is given by Eq. (6),
ASR is defined as for certain number of randomly selected nodes in a network as given in Eq. (7).
Memory overhead: It is defined as the total memory required (in bytes) to store Node KB, Neighbor Node KB and agent codes for identifying trusted neighbors.
Agent overhead: It is defined as the additional number of control packets required to define the agency and their activities that are necessary to implement trusted neighbor selection in WSN.
The simulation is carried out on Pentium IV machine using ‘C’ language. The analysis of performance parameters are given in this section.
Analysis of Average Success Ratio (ASR)
ASR is assessed through simulation to find the effectiveness of the scheme with the varying number of nodes in a network as shown in Fig. 5 for two threshold values

Average success ratio vs. number of nodes.

Average success ratio vs. number of selected nodes (K).
The behavior of ASR with varying number of nodes for different values of K is shown in Fig. 6. As in earlier case, here also ASR increases with increase in the number of nodes. ASR is more for higher value of K is observed since agents may identify more number of trustworthy neighbors as K increases. This is because, a neighbor node may be identified as untrustworthy by one selected node, whereas due to increase in K, the same neighbor node may be proved to trustworthy by another node. Thus, agents are effective in identifying trustworthy nodes. For the obvious reasons, ASR increases with the increase in total number of nodes in a network. Figure 7 shows the increase in ASR with increasing K and ASR is more for higher number of nodes. This is because there is a possibility of more number of neighbors for any given node and among them, the chance of having higher number of trustworthy neighbors is more.

Memory overhead vs. number of selected nodes (K).

Memory overhead vs. simulation time.
In all the cases ASR in TNIWSN is better then NMND because NMND hardly detects malicious nodes behaving normally and detects only malicious nodes with some intelligence which might behave differently from normal nodes.
Additional memory required to store Node KB, Neighbor Node KB and agent codes is shown in Fig. 8 with the number of nodes (K) at which trusted node selection scheme is applied for 150 and 250 node topology. As the selected number of nodes (K) increases where the proposed scheme is applied, there is an increase in neighbor nodes and hence the memory required to store such neighbor information in node’s database increases. However, rate of increase in memory overhead is more after

Agent overhead.
Figure 9 shows memory overhead with simulation time. The oscillatory nature of memory storage depicts the type of node distribution and the effective number of neighbor nodes for which the database is maintained at selected nodes. However, we observe that the memory overhead is higher for more number of nodes in a given topology.
The additional number of control packets necessary to implement the agent based scheme with number of nodes is shown in Fig. 10. We see that agent overhead is increased with increase in number of neighbor nodes since additional number of agents are required to identify trusted neighbors. The increase in agent overhead is remaining constant after 200 nodes since agents take autonomous decisions to identify trusted neighbors by visiting one node to another and if a visited node is found to be untrustworthy, agents kill themselves. With the increase in number of nodes, more agents will be killed thereby agent overhead almost remains constant. Significance of the agents is observed for large scale networks where there is a negligible agent overhead with increase in number of nodes in a network.
Attacks handled by TNIWSN
TNIWSN successfully addresses various types of attacks. The proposal believes on re-computation of Message Authentication Code (MAC) on neighbor node and comparison with MAC computed at sender node. The trustworthiness of neighbor nodes is carried by agents as probability values. Using the trust model presented in the proposal, TNIWSN addresses the following types of attacks: (1) Flooding attack: This attack puts a limit on the number of connections from a particular node. If multiple connections from neighbor nodes are initiated, mobile agent TNA notifies this information to the source SMA, which in turn updates its
Benefits of using agents
Agent based trusted neighbor selection offers flexibility, scalability, efficiency, adaptability and maintainability. We explain below how they are achieved by using the proposed scheme. Flexibility: Agents are flexible to implement trusted node identification in WSN. For example, TNAs generated by SMA clone themselves to visit neighbor nodes and identify trustworthiness of visited nodes. Scalability: The scheme may scale to larger networks since agents function in a distributed fashion thereby it provides similar security level as that of smaller networks. Efficiency: Network efficiency is improved since TNA and SMA agents take autonomous decisions in order to identify trustworthy neighbors. Adaptability: SMA and TNA adapt themselves to dynamic behavior of the network nodes and correctly eliminate untrustworthy neighbor nodes. Maintainability: The components of new agents may be inherited in the components of old agents and thus network maintainability improves with varying conditions. Encapsulation of a protocol: A mobile agent can be coded to perform aggregated tasks such as identification of trustworthy neighbor nodes. Thus, TNAs encapsulate the protocols that are customized based on functionality.
Conclusions
In this paper, we proposed a trustworthy neighbor node identification in WSN using agents through Safeguard Agency. Agents effectively perform the function of finding trusted neighbors using probability based trust model and MAC model ensuring higher security. Two phases are involved in identifying trusted neighbors: in the first phase, agents visit all the neighbors and bring probability of all the neighbors using trust model and in the second phase, agents ensure the trusted neighbors using MAC model. Simulation analysis shows that there is an improvement in average success ratio of finding trustworthy neighbors with little overheads due to the usage of agents. Memory overhead is essential since it requires memory storage to store various node related and neighbor node related information to identify trusted neighbors. The results of TNIWSN outperform compared to the results of NMND.
However, TNIWSN is not capable to address the following types of attacks. (1) Sinkhole and wormhole attacks: Since these attacks relate to secured routing schemes, TNIWSN does not address these attacks as the scope is limited only to identifying trustworthy neighbors. (2) Jamming attack: It is a physical layer attack wherein the radio frequency interference causes signal jamming and it is outside the scope of TNIWSN scheme. Providing security to the agents is another issue. By properly tuning the components of the scheme, we can address some of these attacks and thus we can improve memory overhead and ASR.
The future work can focus on establishing secured routes in WSN using trustworthy neighbors identified by TNIWSN. Other problems that can be addressed are: resource constraints of nodes, various types of attacks, assessment of control and communication overheads, providing security to agents, etc.
Footnotes
Acknowledgements
The authors wish to thank Visvesvaraya Technological University (VTU), Karnataka, India, for funding the part of the project under VTU Research Scheme (Grant No. VTU/Aca./2011-12/A-9/753, Dated: 5 May 2012).
