6LOWPAN ROUTING ATTACK DETECTION IN THE IOT
收藏资源简介:
The Internet of Things (IoT) is increasing in popu- larity, opening up new opportunities for applications in a variety of fields. However, because of the device’s constrained resources and the dynamic topology for networks, The security of the Internet of Things is challenging.Due to the characteristics of the network, routing attacks on 6LoWPAN-based IoT devices can be particularly challenging to identify. Several techniques for detecting routing attacks, including anomaly detection, have been proposed in recent years. These techniques use various characteristics of network traffic to identify and classify routing attacks. This paper focuses on routing attacks against the Routing Protocol for Low-Power and Lossy Networks (RPL), which is widely used in IoT systems based on 6LoWPAN. The attacks discussed in this paper can be classified as either inherited from Wireless Sensor Networks or exploiting RPL-specific vulnerabil- ities. To detect routing attacks, this paper proposes an innovative Hybrid Intrusion Detection System (HIDS) that combines a one- class Support Vector Machine classifier with a decision tree classifier. To identify routing attacks with high accuracy and a low false alarm rate, the HIDS leverages the strengths of both a Signature Intrusion Detection System (SIDS) and an Anomaly-based Intrusion Detection System (AIDS). The routing dataset, which contains genuine IoT network traffic as well as various types of routing attacks, was implemented to run the proposed HIDS through tests. The hybrid IDS proposed in this study outperforms SIDS and AIDS approaches, according to the findings, with higher detection rates and lower false positive rates.
物联网(Internet of Things,IoT)的普及度日益提升,为多领域的应用开辟了全新机遇。然而,由于物联网设备资源受限且网络拓扑动态多变,其安全防护颇具挑战。鉴于物联网网络的特性,针对基于6LoWPAN的物联网设备的路由攻击尤其难以识别。近年来,学界已提出多种路由攻击检测技术,其中包括异常检测方法。此类技术依托网络流量的各类特征,实现路由攻击的识别与分类。本文聚焦针对低功耗有损网络路由协议(Routing Protocol for Low-Power and Lossy Networks,RPL)的路由攻击,该协议广泛应用于基于6LoWPAN的物联网系统中。本文所讨论的路由攻击可分为两类:一类源自无线传感器网络(Wireless Sensor Networks,WSN),另一类则利用了RPL协议特有的安全漏洞。为实现路由攻击检测,本文提出一种创新性的混合入侵检测系统(Hybrid Intrusion Detection System,HIDS),该系统将单类支持向量机分类器与决策树分类器相结合。为以高精度、低误报率识别路由攻击,该混合入侵检测系统融合了基于特征的入侵检测系统(Signature Intrusion Detection System,SIDS)与基于异常的入侵检测系统(Anomaly-based Intrusion Detection System,AIDS)的优势。本文构建了包含真实物联网网络流量与多种路由攻击的路由数据集,用于对所提混合入侵检测系统开展测试验证。实验结果表明,本研究提出的混合入侵检测系统性能优于基于特征的入侵检测系统与基于异常的入侵检测系统,具备更高的检测率与更低的假阳性率。




