论文标题
对基于RPL物联网的DAO感应攻击
The DAO Induction Attack Against the RPL-based Internet of Things
论文作者
论文摘要
RPL是低功率和有损网络(LLN)的新兴路由标准。 LLN是物联网(IoT)的关键组成部分,因此其安全性对于物联网时代至关重要。在这项工作中,我们提出了DAO归纳攻击,这是对RPL的新颖攻击。在此攻击中,恶意内部人士或折衷的节点会定期增加其DTSN号码。每个这样的增量都会在网络中触发/诱导大量控制消息传输。我们表明,这从端到端的潜伏期,数据包损耗率和功耗来降低网络性能。为了减轻,我们提出了一种轻巧的解决方案,以检测DAO感应攻击。我们的解决方案在物联网设备上几乎没有开销,这很重要,因为这些设备通常在功率,内存和处理方面受到限制。
RPL is the emerging routing standard for low power and lossy networks (LLNs). LLN is a key component of the Internet of Things (IoT), hence its security is imperative for the age of IoT. In this work, we present the DAO induction attack, a novel attack against RPL. In this attack, a malicious insider or a compromised node periodically increments its DTSN number. Each such increment can trigger/induce a large number of control message transmissions in the network. We show that this degrades the network performance in terms of end-to-end latency, packet loss ratio, and power consumption. To mitigate, we propose a lightweight solution to detect the DAO induction attack. Our solution imposes nearly no overhead on IoT devices, which is important as these devices are typically constrained in terms of power, memory and processing.