错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Design and Implementation of a Lightweight Mitigation Solution for Addressing Network Partitioning Attack Against RPL Protocol

  • Shefali Goel,
  • Abhishek Verma,
  • Vinod Kumar Jain

摘要

Routing protocol for low-power and lossy networks (RPL) is the standard routing protocol specified by the Internet engineering task force (IETF) for Low power and lossy Nnetworks (LLNs) based Internet of Things (IoT) applications. Although RPL gives many benefits to LLNs, due to the resource-constrained and easily tamperable nature of LLN devices, LLNs are vulnerable to a wide range of attacks that primarily alter the functioning of the RPL. One such attack is known as a Network partitioning attack (NPA). An NPA in RPL occurs when an attacker node intentionally divides a network into disjoint segments, preventing communication between nodes that may be previously able to communicate. This can happen when an attacker does not complete the route registration step at the root node, exploits the rank property of RPL, and continues the standard Destination advertisement object (DAO) forwarding technique of RPL during the node joining and DAG maintenance phase. Consequently, it segregates the section of nodes from the root node. In the literature, Enhanced-RPL (ERPL) is the only solution proposed to address NPA. However, our study shows that ERPL further induces fake Destination Advertisement Object Acknowledgement (DAO-ACK) and dropping DAO Attack, making it unsuitable for deployment in real-world applications. Our analysis indicates that the performance metrics of the network are not improved with the existing mitigation technique when the attacker unicasts fake DAO-ACK packets to victim client nodes. Our key idea is to improve the existing mitigation technique (ERPL) to incorporate an effective NPA detection approach that authenticates the DAO-ACK packet sent from parent nodes to client nodes. Our proposed approach, SecRPLNPA, has been integrated and thoroughly tested using the Cooja simulator. We have conducted a performance assessment of SecRPLNPA comparing it against standard RPL and ERPL. Our empirical results suggest that in both stationary and mobile scenarios, SecRPLNPA proficiently detects and mitigates Network Partitioning Attacks while causing only minimal impact on resource-constrained nodes.