透過您的圖書館登入
IP:3.128.78.41
  • 學位論文

低功率且易失封包的物聯網環境中之網路攻擊行為偵測

DNA: Detection of Networking Attacks in RPL based IoT Networks via Traffic Analysis

指導教授 : 林宗男

摘要


物联网通信范式正在改变着互联网世界。物联网正在引入无限的应用可能性。智能城市,工业自动化,智能家居和智能医疗保健只是可能的物联网应用的一些示例。物联网革命也带来了安全隐患。特别是,受限设备与互联网世界的连接给人类用户的安全和隐私以及其数据的保密性带来了新的威胁。在这种情况下,开发可靠的网络安全机制以完全保护IoT至关重要。此外,物联网网络的子集可能会引入通信功率约束和有损链路。在这些情况下,必须考虑其他注意事项以保护设备之间的通信。 拟议的工作旨在保护RPL(物联网的标准化路由协议)。我们提出CSI,它是一种新颖的入侵检测系统(IDS),可以克服大多数最新IDS的缺点。特别是,CSI引入了一种新颖的嗅探方法,以实现零开销,消除任何计算问题并检测针对RPL的14种不同的攻击。此外,CSI依赖于基于异常的检测和基于签名的分类技术的组合。这两个范例在一个两阶段系统中组合在一起,可以执行可靠的攻击检测,同时保持较小的误报率。为了测试CSI的性能,我们使用NetSim模拟了14种不同类型的攻击。在不同情况下考虑每种攻击,以正确测试CSI的检测能力。结果表明,CSI能够可靠地检测到这些攻击,其性能优于最新的IDS。我们还研究了所提出系统的计算性能,显示了其在现实世界中的适用性。

並列摘要


The Internet of Things paradigm of communication is changing the internet world. IoT is introducing endless possibility of application. Smart cities, Industrial automation, Smart homes and Intelligent healthcare are just some examples of possible IoT applications. The IoT revolution brings also security concerns. In particular, the connection of constrained devices to the internet world produces new threats for human users safety and privacy, as well as to the secrecy of their data. In this scenario it is fundamental to develop reliable cybersecurity mechanisms to protect completely IoT. Moreover, subsets of IoT networks may introduce communication power constrains and lossy links. In these scenarios, additional considerations must be taken into account to secure communication between devices. The proposed work aims at securing RPL, the standardized routing protocol for IoT. We propose CSI, a novel Intrusion Detection System (IDS) that overcomes most of state-of-the-art IDSs' drawbacks. In particular, CSI introduces a novel sniffing approach to reach zero overhead, remove any computational issue and detect 14 different attacks against RPL. Moreover, CSI relies on the combination of anomaly-based detection and signature-based classification techniques. The two paradigms are combined in a two-stages system to perform reliable attack detection, while maintaining small false positives rate. To test CSI's performances we simulate 14 different classes of attacks using NetSim. Each attack is considered in different scenarios to test properly CSI's detection ability. Results show that CSI reliably detects these attacks, outperforming state-of-the-art IDSs. We study also the computational performances of the proposed system, showing its applicability to real world scenarios.

參考文獻


[1] Kleinrock,Leonard. “An earlyhistoryofthe internet
[HistoryofCommunications]”.In: IEEE CommunicationsMagazine 48.8 (2010),pp.26–36.
[2] Mainetti,Luca,Patrono,Luigi,andVilei,Antonio.“Evolutionofwireless sensor networkstowardstheinternetofthings:Asurvey”.In: SoftCOM 2011, 19th internationalconferenceonsoftware,telecommunicationsandcomputer networks. IEEE.2011,pp.1–6.
[3] Gaikwad,PranayP,Gabhane,JyotsnaP,andGolait,SnehalS. “A surveybasedonSmartHomessystemusingInternet-of-Things”.In: 2015 International ConferenceonComputationofPower,Energy,Informationand Communication (ICCPEIC). IEEE.2015,pp.0330–0335.
[4] Stojkoska,BiljanaLRisteskaandTrivodaliev,KireV.“AreviewofInternet of Thingsforsmarthome:Challengesandsolutions”.In: Journal ofCleaner Production 140 (2017),pp.1454–1464.

延伸閱讀