1. Introduction
A wireless sensor network (WSN) is a modern technology that significantly affects our everyday life and work by relying on wireless communication links rather than wires. WSNs have the capabilities of sensing, processing, and communicating the signal to a base station (BS), which has applications in various fields. However, WSNs are vulnerable and permeable to the maliciousness of all kinds of attacks because of some security constraints that are a real security challenge to be faced, especially when the exchange concerns sensitive data that must reach the end-user [
1,
2]. A sensor consists of five layers: the link, application, MAC, and physical layers. Each one of these layers could be targeted by an intruder for specific purposes with a plan to eavesdrop on the WSN. So, it is necessary to minimize the risk of attack and transmit data to the end-user without being received in promiscuous mode [
3,
4]. Also, the nodes are resource-constrained [
5,
6,
7], the WSNs have unique identification (ID), and they communicate with each other by the multi-hops mechanism. WSNs are exposed to acute security problems compared to wired mediums by being an open-air medium.
Ad hoc network-specific security risks do not include vulnerabilities in operating systems or upper-layer user applications like databases, browsers, or client–server programs. The ad hoc network’s routing layer, which includes the physical, MAC, and network layers, is the primary target of general types of assaults. In wireless ad hoc networks, these layers are necessary for routing operations and packet forwarding following route discovery [
8,
9,
10].
Security measures remain important in WSN to guarantee authentication, availability, confidentiality, privacy, no repudiation, anti-playback, and integrity [
11,
12]. We can conclude that they must possess a particular degree of security to effectively monitor where they are used and to ensure that the message and information are not altered during communication. So, data integrity is a mandatory operation that guarantees that the message does not alter, replay, or get spoofed during the transfer. The authentication of the message is still crucial in this situation since there is a chance that a hacker might access, rebroadcast, and edit messages as well as block the link to occupy the sensors. The integrity of the data is another aspect of this security method that is taken into consideration; each packet has a timestamp appended to it to ensure that no message is repeated. Additionally, data should be recent because, in such a network, shared data must come from reliable sources and is particularly sensitive. To prevent possible intruders from intercepting or reprogramming the content of signals shared by sensors, communication must be kept private and confidential [
13]. So that potential intruders are unable to intercept or reprogram the content of messages shared by sensors [
3]. If not well protected, the network is at risk of going into promiscuous mode under malicious attacks [
14,
15,
16]. This is the case with our attack, where the hacker node attracts the neighboring node using a higher sequence number, an incorrect route response, using fewer hops, and never broadcasting the received RREQ as it is required by the route discovery process [
4]. Various network layer attacks occur by modifying or adding some elements of routing messages, like the hop count or sequence number. Such types of attacks are hard to detect. They always try to destroy or alter the information. Therefore, WSNs should incorporate each of the three components of prevention, reaction, and detection to guard the system against collapse [
2,
8,
17].
To fight attacks, many researchers have proposed various methods with a higher level of safety, despite the fact that each has a unique defense object and is unable to defend against a specific attack [
18]. The WSN protocol should perform well in a variety of network situations, from minor ad hoc groups to bigger mobile networks. The AODV routing protocol is widely utilized in WSN technology. However, this protocol remains vulnerable to security threats such as black hole attacks [
19]. This occurs when a malicious node sends a fake route reply message to a destination node. The message contains a short and recent path to the intended destination and uses higher sequence number, which is an important attribute in routing since it indicates the freshness of the route from the source. Therefore, any information that attempts to reach the black hole node fails and ends up getting captured, resulting in low data and a significant end-to-end delay that we will address in the simulation section. It is critical to investigate how effective the WSN is against black hole attacks and how the implementation of an intrusion detection system (IDS) mechanism in the AODV routing protocol in the WSN might help to mitigate its impact. Applying IDS to the WSN architecture is the suggested remedy in this article. The “recv Reply” function was used to determine whether or not the RREP message has arrived. If so, the function indicates that the RREP message has already arrived by displaying it. If not, it executes the standard RREP function; if the RREP message for the same destination address has already been queued, it stores it and returns it from the function. Assessing how the WSN performs under black hole attacks and the methods to prevent them is important for comprehending how this solution functions. We presented our work at “IBICA’17”.
This article consists of ten sections: The initial part will tackle the misbehavior mechanism within sensor networks, and then
Section 3 will address the present risks in WSNs.
Section 4 offers and discusses the existing literature of the proposed method used to defend against these attacks.
Section 5 introduces an AODV protocol that operates as the black hole nodes in NS2. Two scenarios have been assessed, each one of them is composed of 25 nodes, all employing the AODV protocol. Moreover, the same scenarios will be simulated by adding between one and five malicious nodes into the network. A solution will also be proposed in order to minimize the impact of these attacks on NS-2. A thorough description will be provided in
Section 4 explaining the various types of IDS for WSN. And in
Section 7, the suggested algorithm offers an intrusion detection system founded on the AODV protocol, to counter against black hole nodes which is possible in most on-demand routing protocols, even secure ones, such as SAR (Secure-Aware Ad Hoc Routing protocol), ARAN (Authenticated Routing for Ad Hoc Networks), SAODV, SRP, ARIADNE, etc. [
20].
Section 8 will introduce the simulation setup and
Section 9 will present the analysis. Finally,
Section 10 concludes this research.
2. Misbehavior Model for Wireless Sensor Networks
The network has the following advantages: broadcasting character, wireless connectivity, transmission medium, cooperative algorithms, autonomous behavior of nodes, a collaboration between sensors; however, these characteristics are also the reasons why WSNs are prone to security attacks, for instance, when the network is subjected to some specific conditions and scenarios, particularly in situations when a stranger is manipulating the data and has access to it [
8]. The question is, what does the attacker want from the targeted network? This question specifies the attack faced by the proper user (see
Figure 1). Also, it may be due to the simplicity of the routing protocol used to forward packets from one node to another, which is strictly required to maintain their connectivity over a wireless open medium in a distributed manner [
20,
21,
22]. All these factors help attackers interrupt the network by, for example, transforming the routing protocol used to forward data to a central location (the “Sink”) and by interfering network operations through techniques like selective forwarding, packet drops, or data fabrication [
15]. This will make other attacks against this specific form of ad hoc networking viable. Sensors are forced to interact with unpredictable environments where they may be subjected to a range of physical, biological, and chemical forces. Therefore, in the absence of wired networks, these networks must present specific security problems, and different management mechanisms must be implemented to increase their dependability. Because each attack has a unique defense mechanism, researchers must comprehend the many types of attacks and how they affect WSNs in order to guarantee secure communication and transmission [
21].
Additionally, a node may deteriorate dramatically as if it were injured. A node that is unable to operate on the network due to a malfunctioning battery could be seen as an attack. Selfishness is another bad trait; selfish nodes avoid using their resources, including battery power, by abstaining from network activity. Because they improperly process network packets, such as in routing systems, failed and selfish nodes also have an impact on network performance.
Until now, almost all common routing protocols considered performance a priority and had little detection and defense ability against malicious nodes [
23]. There are several types of routing protocols, including flat, data-centric, QoS-Based, geographical, multipath, and hierarchical routing. This classification is shown in
Table 1. Due to node mobility and concentration, these protocols are usually deployed at high densities (approximately 20 sensors/m
3), which leads to increased energy consumption. As a result, WSNs have a high degree of redundancy in communication and sensing, which frequently causes packet collisions [
24]. Compared to local processing, data transmission to the base station uses more energy, and extended delays may occur between transmissions. Furthermore, the network’s most energy-intensive component is the RF module, which is in charge of wireless communication [
22]. Thus, the principal objective of any routing protocol is to efficiently transfer data to end users while consuming the least amount of energy possible, and the network lifetime must be effectively increased. Since routing protocols are an essential part of network functionality, an efficient WSN design must ultimately be energy-efficient to preserve network operability and satisfy application requirements [
25].
Among the challenges of routing in WSNs, two important issues are energy efficiency and security [
25,
30]. Therefore, for the majority of current research in WSN, security methods and routing protocols are typically handled independently rather than built together [
18,
31]. Numerous researchers have proposed various safety protocols to guard against attacks. Each attack, however, has a unique set of countermeasures. Knowing what needs to be secured will be necessary to achieve security goals for sensor networks [
22,
30]. For the purpose of meeting the requirements of different applications, the routing protocols for wireless sensor networks should ensure maximum energy efficiency [
32]. Since it is commonly acknowledged that it is not possible to always avoid or neutralize the attacks, intrusion detection is needed as supplementary protective measure. It is crucial to ensure the sensor network is safeguarded from cyber threats. Also, detecting intrusions is the objective of Intrusion Detection Systems (IDSs), which already exist as a tool for ensuring cybersecurity in traditional computer-based systems. IDSs can also propose additional mechanisms, such as prevention and diagnosis.
The fundamental characteristics are essential for the flexibility of WSNs. However, their vulnerabilities, such as insecure communication, broadcasting mechanisms, wireless connectivity, transmission medium, and sensor node dynamic behavior, make them vulnerable to a variety of attacks. So, particular security considerations that are missing in wired networks should be introduced in WSNs [
21]. Because of the simplicity of the routing protocol used to transmit packets from one node to another, they must maintain distributed connectivity over a wireless open medium in a distributed manner [
15,
22,
28]. Hence, the sensor node in the WSN is free to advance independently in any direction [
33].
Because of how scarce some resources have become compared to before, WSNs can easily face many security attacks when attackers exploit system vulnerabilities [
30]. Furthermore, security systems do not prevent sensor nodes from misbehaving since these nodes’ wireless radios are severely affected by environmental conditions [
34]. Additionally, communication errors that frequently occur in WSNs are often caused by outside interference. The attacker may use potential routes that the sender selects to transmit data and exploit the weaknesses in the routing protocol, giving him the opportunity to perform many attacks or gain unauthorized access. Through this action, they can seriously damage the network’s topology by rerouting data or disrupting routing procedures. This might force nodes to disregard valid neighboring nodes or cause them to wrongly include neighbors that are not actually there. Because every route must go through a black hole node that cannot build a correct routing path between the starting and ending points, attacks can aim at the OSI layers within the network structure [
35,
36]. And the effect of the attacker is greater if the attacker has more than one compromised node. Because a node may misbehave in a variety of ways, such as dropping data (black hole attack), forwarding data selectively, or going into sleep mode (snooze attack), this behavior of the intruder will influence the data reaching the base station and can affect the overall decision taken by the last user based on the collected data [
11,
16].
To sum up, the attackers always try to exhaust the energy of the sensor nodes. Also, attackers can use nodes with larger computing resources, such as laptops, to attack the nodes [
6,
15]. Laptop attacker nodes can communicate with sensors, introduce malicious code, and turn them into compromised nodes to violate their security mechanisms. These compromised nodes remain among the most damaging attacks on the WSN. They can target a specific computer component, a certain network infrastructure, or an entire computer system, or even the entire internet infrastructure. As a result, each attack brings its own set of benefits and characteristics to the network [
34]. To cover different classes of misbehavior,
Figure 1 gives a global view of the network under both promiscuous mode and normal situations.
These attacks are grouped into four types: passive, active, internal, and external. In an active attack, the attacker exploits weaknesses in the security protocol to initiate attacks such as replaying, packet modification, DOS, spoofing, fabrication, node subversion, man-in-the-middle attacks, selective forwarding, etc. During a passive attack, the attacker obtains access to information like traffic monitoring, eavesdropping, and traffic analysis without being detected. These types of attacks are difficult to detect, and adversaries simply establish them to intrude on network data exchange. Detection is particularly challenging since the network structure remains unaltered. In the situation of an external assault on the network, the intruder is external and lacks privileges to reach the network, including eavesdropping attacks, denial-of-service attacks, and resource exhaustion [
12,
23]. Lastly, an internal assault happens when it is granted authorization to reach the network; the intruder, in this instance, uses a harmful node to compromise the sensor nodes and take control of the network [
27]. The intruder may use various strategies to carry out malicious behavior on the network. Thus, it proves difficult to discover one broad approach that will function effectively for every kind of assault on WSNs [
23]. In this context, many threats [
34] are detailed, such as gray hole [
31], Sybil, false or malicious node [
16], flooding, wormhole [
21,
29], Byzantine, node capturing, passive, selective forwarding, resource consumption, Location Disclosure Attack [
1,
4], and the black hole attack, which is the focus of this study. Once the type of attack is well understood, appropriate strategies can be applied to confront it, as each attack possesses its own specific defense mechanism.
This study focuses on the black hole attack that a hacker node conducts against the AODV routing protocol and the demonstrated mitigation method based on the RREP message on the AODV routing protocol. A summary of different attacks is shown in
Table 2.
3. Related Works
Researchers propose numerous techniques and methods to detect and prevent black hole attacks in mobile ad hoc networks. In this regard, some of these works are presented below.
Deng, Li, and Agarwal [
1] have proposed a mechanism to reject the route that contains the malicious node, which involves employing the route reply packet received from one of the intermediate nodes and the route request sent from the source node to a neighbor node to ensure that such a path exists from the intermediate node to the destination node. So, the source node S sends route request packets and receives a route reply through the intermediate node. However, if the intermediary node is a malicious node, the source node S will send Further Route Request packets to its neighbor node E to see if it has a routing list for this malicious node M. If not, node E is chosen as the new route to the destination. This approach is effective only when there is a single attacker; it is ineffective when there are multiple attacker nodes and cannot identify a cooperative blackhole attack. Meanwhile, a cooperative black hole assault is addressed by the technique used in [
24] and in [
37] for team black hole attacks.
An approach has been proposed in [
11], which involves dynamically calculating a PEAK value after a fixed time interval by an intermediate node that uses three parameters for calculation: the routing table sequence number, the RREP sequence number, and the number of replies received at the time interval. This peak value is regarded as the highest value of a sequence number that any route response could possibly have at this time. The routing table marks the malicious node that sent the received RREP as one that should not be considered (DO_NOT_CONSIDER). Then, the received RREP is routed back to the source node through the reverse path. The advantage of this method is that no requirement is needed for any additional control packets added to the proposed algorithm. In the same way, the malicious nodes are isolated, and the Packet Delivery Ratio (PDR) is improved considerably.
Also, S. Ramaswamy et al. [
24] proposed an algorithm to prevent cooperative black hole attacks in ad hoc networks. It is based on establishing a trustful relationship between the nodes by introducing the Data Routing Information (DRI) table and cross-checking. The gray hole attacks cannot be tackled because of intensive cross-checking. This algorithm requires more time to complete, even when the network is not under attack.
A watchdog-based method is developed in [
26]. A node keeps copies of the watchdog-forwarded packets in a buffer to ensure that it sends packets properly. It is necessary to track the transmission of next-hop neighbors and identify problematic nodes to accomplish this. The overheard packet is compared with the one that is stored in the buffer, and if there is a match, the packet in the buffer is removed. Alternately, the watchdog increases the node’s failure count, which is responsible for packet forwarding. The failure count surpasses a predetermined threshold when the node is identified as the misbehaving node, and a notice is issued and a message is delivered to the source node.
The passive overhearing-based watchdog method in [
38] could only determine whether the next-hop neighbor has sent packets. Otherwise, it is unable to determine the receiver’s level of reception compared to [
26] in which a buffer is used. The acknowledgment of packets forms the foundation of the scheme [
39]. It is intended to address this problem. When a packet is sent by the source node, it waits for an acknowledgement packet from the destination node. Each node along the reverse route sends an acknowledgment back to the source node after the destination node has received a packet. An acknowledgment packet is successfully sent after the packet transmission. If not, a message of alarm is generated.
Z. Karakehayov [
37] proposes a REWARD based on the routing algorithm to detect team black hole attacks in wireless sensor networks. In this method, the transmission of the sensor node performs power control for more than one sensor node in the direction of the BS through packet transmission. If a packet fails to forward an SN along the route, its neighbor will notice and report the SN as the black hole node in the next hop. REWARD uses geographic routing for forwarding. For its broadcast messages, the algorithm uses two different types; it brings together a dispersed database for identifying the SAMBA and MISS black hole attacks. MISS can help with the identification of malicious nodes working in the ID space. Likewise, SAMBA can provide the location of the detected black hole attacks related to physical space.
The author [
32] proposes ANB-AODV (Anti Near Black hole-AODV) to mitigate the impact of a black hole attack in MANET. So, when the source node broadcasts the RREQ packet, the first route reply will be from a malicious node to the source node, especially when this node is near the source node. Mostly, the source node will accept the first reply coming from the malicious node and start sending data packets. But when the second reply comes from the original destination after some time, it will accept the second reply and start sending through this alternative path. As for AFB-AODV (Anti-Far Black hole-AODV), the source node will accept the first reply that comes from the original destination node and reject the second reply. It has proposed a black hole attack approach that is effective for network performance. So, there is a decrease in packet loss when the ANB-AODV and AFB-AODV protocols are used. Furthermore, it improves the network’s performance.
The author proposed a Secure Protocol for RElibled at a Delivery (SPREAD) in MANET in [
40]. End-to-end delivery is intended. The secret-sharing technique breaks up shared data into smaller chunks and sends them over through one or more independent pathways to their destination. As an alternative, dropping the single shortest channel for data routing between nodes is used. SPREAD performs better in terms of enhancing security. Its advantage is that it can withstand collusion attempts with more compromised nodes up to a certain number. The goals of multipath-based systems appear to be in conflict, particularly regarding the quantity of information that must be redundant.
Another related study [
41] proposed the ERDA (Enhanced Route Discovery) method as a straightforward fix to eliminate misleading route entries. It requires less effort to mitigate the impact of black hole attacks. Additionally, it functions without altering the current protocol scheme. This technique improves routing update functionality and separates malicious black hole nodes by analyzing received reply control messages (RREPs). The black hole feature is a high supported destination sequence number in the route reply, and this technique assumes that the destination node is reachable via route request.
In [
19], the authors proposed the DPRAODV method, a dynamic learning system against black hole attacks in AODV-based MANET. The black hole node is prevented by informing other nodes in the network and setting a threshold. So, by sending the RREP sequence number (RREP_seq_no), we can check whether the sender is an attacker or not. If we consider that the value of (RREP_seq_no) is higher, the sender will be detected as an attacker and will be added to the blacklist. Then, it will be treated as a malicious node and ultimately will be blocked by not processing any of the RREPs. The essential advantage of this protocol is that the source node declares the black hole to its neighbors as something to be ignored and removed. However, the cooperative black hole nodes are not supported by this method. Also, an overhead of updating threshold values at every time interval and the generation of the ALARM packet will significantly increase the routing even further.
5. Summary of IDS in WSN
Intrusion detection systems (IDSs) can identify both internal and external network threats in a sensor network. Unlike other security measures like cryptography, which shield the network from outside attackers [
5]. IDS for sensor networks must notify the base station of any anomalies [
7,
31]. Nevertheless, the direct use of the IDS solutions created for ad hoc networks in sensor networks is impossible since it is impractical to have an active, fully powered agent within every node of a sensor network. Irregular detection methods may still be utilized for the purpose of tracking these measures because their objective is still highly specific: to quantify the physical data (sound or temperature, for example) of its environment. As a result, hardware modules and configuration protocols are extremely specialized [
42,
43]. The nodes that originate from the actual world and adhere to specific parameters and patterns read all data. It is very difficult to create a lightweight detection technique for every protocol that is currently in use, owing to the huge number of protocols and packet formats provided in the literature, particularly in routing algorithms [
10]. At this point, we can see that node sensed data is also susceptible, and hackers can try to affect this process for their interest. However, some partial fixes permit a node to monitor the data exchange, confirm the integrity of the code inside the node, or check the condition of a group of nodes to learn if they are alive or dead in order to confirm the security of the sensing infrastructure. Although this method could be integrated into a system for spotting intrusions, no solution has been created particularly to interface with different schemes. Because of this, the IDS needs to be straightforward and highly tailored to the particular protocols used across the network and for responding to particular threats to sensor networks [
9].
Figure 3 shows the classification and types of IDS. Security is still required in this aspect to allow nodes to communicate securely in a potentially hostile environment. That has traditionally been a hotly debated subject in wireless networks research. However, due to factors like limited resources and robust security measures, these cannot be introduced to avoid sensor node misbehavior as doing so would probably result in anomalous network operation.
The preventive mechanisms and security services, such as access controls and authentication services, can improve the security of ad hoc networks, but they cannot deter all possible insider attackers [
9,
33]. Especially when a denial-of-service (DOS) occurs, when an entity cannot execute an action or access a service that it is entitled to. This is the reason why analyzing environmental data is the primary task of the sensor node, and attackers may attempt to affect this process for their own benefit. Thus, all information is collected by the nodes coming from the real world and that meet the identified patterns and thresholds [
30]. Hence, it is necessary to have other security mechanisms to treat misbehaving insider nodes which possess access rights. The majority of these measurements may be monitored using anomaly detection techniques. Any change in the accelerometer’s reading suggests that the node is stolen by an unauthorized party, and an alarm will sound. Moreover, the local agent monitors packets sent straight to the node. Also, in case a node takes long to transmit a packet due to the channel unavailability. Misuse methods may be used to detect an unusual activity or situation that requires raising a warning. The local agents are there to look for threats or attacks that might interfere with the sensor nodes’ typical operation. This can be accomplished by focusing solely on local data sources, such as the node’s real status, packets it broadcasts and receives, all of its neighbors’ known information, and environmental measurements [
42]. But those attacks must be recognized by the local agency. In a nutshell, the security measure should guard against both external and internal system intrusions. Because this last relies on the collective protection of all nodes and, in particular, lacks centralized monitoring in a wireless sensor network and management points, it should not be for a single layer in the network but should instead protect each node [
30,
33].
6. Algorithm AODV-IDS
This process supposes that the route request is able to access the destination node, and that the regular black hole feature is the high destination sequence number supported in the path response. This sequence number is used to identify the path from source to destination. Moreover, SN (the source node) claims to have the shortest route to the destination. The solution in this case is based on the intrusion detection system (IDS), processing the first RREP (Route Reply) coming from the black hole node by analyzing its sequence number in this RREP packet in order to check if it exceeds the sequence number at the source. In this situation, the AODV (Ad hoc On-Demand Distance Vector) network classifies the node that sent this RREP packet as a malicious node. AODV borrows the concept of “destination sequence numbers” from DSDV for maintaining the most recent routing information between nodes. When immediate communication is absent, nodes do not maintain or establish paths to other routes, but the former node offers its services as an intermediate forwarding station to maintain connectivity between other nodes. An adversary node or sequence number intrusion is considered as one of the active attacks that happens in the network’s routing by transmitting fake path response messages and declaring them as the shortest route to the target node. The other nodes will accept it by selecting its route, and they will begin gathering all the information packets from nodes nearby and then drop all the processed packets, causing the communication to be delayed or be blocked in the networks. This solution is used in order to concentrate on analyzing and enhancing the security of the AODV (Ad hoc On-Demand Distance Vector) routing process and to what extent IDS utilization helps in securing WSN to combat this attack, notably, concerning packet loss and transmission delay mitigation. The routing table contains information about the path to a destination because every node in an ad hoc network maintains it. Consequently, adversaries have an influence on every possible route that might be used by the transmitter to deliver data across the network. The data collected from the hacker through the DSN determines this assertion. We had to change the RREP function (recv Reply) and create an RREP caching mechanism to count the second RREP message in order to implement the solution. For this purpose, this algorithm is implemented by changing the normal receive RREP function (recv Reply) and replacing it with an RREP caching mechanism to count the second RREP message. In the “recv Reply” function, we first check if the RREP message has arrived for itself, and if it has, the display function of the RREP message if it has already arrived. If this is not the case, it inserts the RREP message for its destination address. Also, if the RREP message is cached previously for the same destination address, the normal RREP function is performed. Subsequently, if the RREP message is not destined for itself, the node transmits the message to its appropriate neighbor. In addition, there are four sub-functions added to the RREP caching mechanism, namely, “rrep_insert”, “rrep_lookup”, “rrep_remove”, and “rrep_purge”, and each sub-function has its own role, as mentioned in
Figure 4, to prevent the first or second RREP from coming from the black hole node.
In the following flowchart (
Figure 5 [
21]), the mechanism of this technique is presented.
The black hole node typically does not check the routing database for acceptable routing options as it would in typical cases because it generates an instantaneous response. Due to this, the false malicious node contributes to the network with the exceeded destination sequence number, but either the false node or the genuine destination node will propagate the first path response. The latter may be saved in the RR-Table’s entry.
This first RREP packet from the false node will be dropped by the IDSHNAODV algorithms and the second RREP packet from the destination will be chosen instead, eventually discovering another route to the destination. Lastly, it compares the first destination sequence number with the source node sequence number, and the node is malicious if there are more differences between them. Consequently, that entry from the RR-Table gets removed.
9. Results and Discussions
In order to assess the performance of WSN during attacks, a simulation study has been conducted using metrics such as packet loss, throughput, end-to-end delay, and average energy. Five attackers are present according to the results in
Figure 3. Under malicious attacks as shown in
Table 4, AODV drops more packets than normal AODV when there is a varying number of communicating nodes (see
Figure 6). Because the attacked node prevents additional packets from flowing to neighboring nodes, it is concluded that conventional AODV (without malicious attacks) has fewer packets to lose than AODV with malicious attacks Also, the IDS protocol has been used in the presence of a black hole adversary malicious node for the purpose of checking the network’s performance. First, we vary the number of nodes to measure packet loss, throughput, delay, and energy. Thus, we set the number of malicious nodes to 4 (see
Figure 7). With the aim of comparing among AODV, AODV in the presence of a black hole attack (HNAODV), and IDS when this attack is occurring, we have fixed the number of malicious nodes to one in the remaining graphs. In the simulation test, the black hole node is selected randomly and causes the network’s delay to increase. The findings of this simulation are presented in
Figure 8,
Figure 9,
Figure 10,
Figure 11 and
Figure 12, showing the network throughput, average delay, average energy, and packet loss with and without an attack and an IDS protocol, respectively.
AODV experiences higher packet loss when more malicious nodes drop more packets. Additionally, it does not permit the packet to continue; rather, it occurs because all packets that pass through the attacker’s route are discarded and absorbed, which significantly reduces the number of packets delivered. It is so because the intruder has to disable the sender by not broadcasting the RREQ that is received from intermediate nodes.
From
Figure 7, it can be concluded that the number of packet losses rises when the number of hackers increases. So, when the number of malicious nodes rises, the network enters into promiscuous mode, causing packet loss to increase.
According to
Figure 8, as the number of malicious nodes increases, throughput will decrease. Because each malicious node exists in the network instead of transmitting the packets, it drops all the packets it receives.
First, in the absence of an attack graph, it sends bits from the source to the destination node. Following that, we introduce one false node into the network; this false node is the black hole (a natural hacker). Then network latency occurs (see
Figure 9).
In comparison with AODV, (IDSHNAODV) exhibits a low delay in
Figure 9, and the more nodes there are in AODV, the higher the delay will be in the event of a black hole attack. The security of the wireless sensor network is further complicated by the fact that all nodes are mobile and the network topology is constantly shifting in a WSN. Low throughput and high end-to-end delay result in any data entering the black hole region being dropped and unable to reach its destination. The routing protocol (AODV) performs worse when malicious nodes are added, as shown in
Figure 10 because the malicious attack will lower throughput; this is particularly true as the number of nodes increases (
Figure 8). Attackers may, therefore, modify node behavior, altering the results.
Figure 10 shows that as the number of communicating nodes rises, so does the AODV routing protocol’s throughput. However, when malicious attacks occur, AODV’s throughput is reduced in comparison to regular AODV. Throughput calculates the network’s performance in regular conditions under a black hole attack and in the presence of an IDS to improve the network’s operation. And it shows the throughput results of Ad hoc On-demand Distance Vector (AODV), AODV in the presence of one adversary node, and (IDSHNAODV) with the attack.
It is clear from the graph that we observe a significant improvement in throughput results for (AODV) and (IDSHNAODV) under the black hole node for a 10 nodes scenario compared to only AODV under the attacker (HNAODV). As the number of nodes increases, throughput decreases.
Figure 11 makes it evident that the number of nodes directly correlates with energy consumption. Because of that, all AODV, HNAODV, and IDSHNAODV protocols automatically minimize energy consumption as the number of nodes rises. Since a node’s energy will not be noticeably mitigated by adding a few tasks such as IDS, all protocols will have similar energy. Conversely, it ought to be insignificant.
According to
Figure 12, normal AODV (in the absence of an attack) has less packet loss than AODV with a malicious attack because nodes that are under attack prevent additional packets from passing to nearby nodes. Then, we have measured the packet drop of AODV with the black hole under the IDS approach, and in this case, packet loss increases. By dropping data packets in the network, the hacker node created by the black hole attack affects routing performance, as the graph makes clear. Following the establishment of the route via that node, the nearby node starts forwarding packets, which are ultimately dropped at the adversary. Therefore, as the number of malicious nodes increases, their effect increases further. In the presence of malicious attacks, AODV drops more packets than usual when there are varying numbers of communicating nodes (see
Figure 12). Finally, the increased number of attackers will affect the performance of all metrics on the network.