{"title":"基于基尼指数的物联网网络攻击防范对策","authors":"Bryan N. Groves, Cong Pu","doi":"10.1109/MILCOM47813.2019.9021050","DOIUrl":null,"url":null,"abstract":"As an essential ingredient of Internet of Things (IoT), IPv6-based Low Power and Lossy Networks (LLNs) largely consisting of various resource-constrained devices are expeditiously proliferating and playing an important role in the realization of ubiquitous computing and communication infrastructure. In order to provide efficient and reliable communication between resource-constrained devices and connect them to the Internet, a novel routing protocol for LLNs, a.k.a. RPL, has been proposed. However, due to wide distribution, openness, and instinctive resource constraints of IoT devices, IoT and its applications become an ideal target for cyber attacks. Thus, investigating potential attacks against IoT-related routing protocol is a top priority to improve the security of the future IoT systems. In this paper, we propose a Gini index-based countermeasure to effectively detect and mitigate sybil attack in RPL- based LLNs, where the malicious node multicasts an excessive number of DODAG Information Solicitation (DIS) messages with different fictitious identities to cause the legitimate nodes to restart the Trickle algorithm frequently and broadcast a large number of DODAG Information Object (DIO) messages to quickly drain the limited energy resource of legitimate nodes. We conduct extensive simulation experiments for performance evaluation and comparison using OMNeT++, and the simulation results show that the proposed countermeasure can accurately detect and effectively mitigate sybil attack, indicating a viable approach against cyber attack in the Internet of Things.","PeriodicalId":371812,"journal":{"name":"MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM)","volume":"68 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":"{\"title\":\"A Gini Index-Based Countermeasure Against Sybil Attack in the Internet of Things\",\"authors\":\"Bryan N. Groves, Cong Pu\",\"doi\":\"10.1109/MILCOM47813.2019.9021050\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"As an essential ingredient of Internet of Things (IoT), IPv6-based Low Power and Lossy Networks (LLNs) largely consisting of various resource-constrained devices are expeditiously proliferating and playing an important role in the realization of ubiquitous computing and communication infrastructure. In order to provide efficient and reliable communication between resource-constrained devices and connect them to the Internet, a novel routing protocol for LLNs, a.k.a. RPL, has been proposed. However, due to wide distribution, openness, and instinctive resource constraints of IoT devices, IoT and its applications become an ideal target for cyber attacks. Thus, investigating potential attacks against IoT-related routing protocol is a top priority to improve the security of the future IoT systems. In this paper, we propose a Gini index-based countermeasure to effectively detect and mitigate sybil attack in RPL- based LLNs, where the malicious node multicasts an excessive number of DODAG Information Solicitation (DIS) messages with different fictitious identities to cause the legitimate nodes to restart the Trickle algorithm frequently and broadcast a large number of DODAG Information Object (DIO) messages to quickly drain the limited energy resource of legitimate nodes. We conduct extensive simulation experiments for performance evaluation and comparison using OMNeT++, and the simulation results show that the proposed countermeasure can accurately detect and effectively mitigate sybil attack, indicating a viable approach against cyber attack in the Internet of Things.\",\"PeriodicalId\":371812,\"journal\":{\"name\":\"MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM)\",\"volume\":\"68 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"14\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MILCOM47813.2019.9021050\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MILCOM47813.2019.9021050","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14
摘要
基于ipv6的低功耗损耗网络(Low Power and Lossy network, lln)作为物联网的重要组成部分,在实现泛在计算和通信基础设施方面发挥着重要作用。为了在资源受限的设备之间提供高效可靠的通信并将其连接到Internet,提出了一种新的lln路由协议,即RPL。然而,由于物联网设备的广泛分布、开放性和本能的资源约束,物联网及其应用成为网络攻击的理想目标。因此,调查针对物联网相关路由协议的潜在攻击是提高未来物联网系统安全性的首要任务。本文提出了一种基于Gini指数的策略来有效检测和缓解基于RPL的lln中的符号攻击,恶意节点以不同的虚拟身份广播过多的DODAG Information Solicitation (DIS)消息,导致合法节点频繁重启涓滴算法并广播大量的DODAG Information Object (DIO)消息,以快速耗尽合法节点有限的能量资源。利用omnet++进行了大量的仿真实验进行性能评估和比较,仿真结果表明,所提出的对策能够准确检测并有效缓解符号攻击,为物联网环境下的网络攻击提供了一种可行的方法。
A Gini Index-Based Countermeasure Against Sybil Attack in the Internet of Things
As an essential ingredient of Internet of Things (IoT), IPv6-based Low Power and Lossy Networks (LLNs) largely consisting of various resource-constrained devices are expeditiously proliferating and playing an important role in the realization of ubiquitous computing and communication infrastructure. In order to provide efficient and reliable communication between resource-constrained devices and connect them to the Internet, a novel routing protocol for LLNs, a.k.a. RPL, has been proposed. However, due to wide distribution, openness, and instinctive resource constraints of IoT devices, IoT and its applications become an ideal target for cyber attacks. Thus, investigating potential attacks against IoT-related routing protocol is a top priority to improve the security of the future IoT systems. In this paper, we propose a Gini index-based countermeasure to effectively detect and mitigate sybil attack in RPL- based LLNs, where the malicious node multicasts an excessive number of DODAG Information Solicitation (DIS) messages with different fictitious identities to cause the legitimate nodes to restart the Trickle algorithm frequently and broadcast a large number of DODAG Information Object (DIO) messages to quickly drain the limited energy resource of legitimate nodes. We conduct extensive simulation experiments for performance evaluation and comparison using OMNeT++, and the simulation results show that the proposed countermeasure can accurately detect and effectively mitigate sybil attack, indicating a viable approach against cyber attack in the Internet of Things.