A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks
Internet of Things (IoT) systems incorporate a multitude of resource-limited devices typically interconnected over Low Power and Lossy Networks (LLNs). Robust IP-based network routing among such constrained IoT devices can be effectively realized using the IPv6 Routing Protocol for LLN (RPL) which i...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2022-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9923901/ |
_version_ | 1811198349313835008 |
---|---|
author | Ibrahim S. Alsukayti Aman Singh |
author_facet | Ibrahim S. Alsukayti Aman Singh |
author_sort | Ibrahim S. Alsukayti |
collection | DOAJ |
description | Internet of Things (IoT) systems incorporate a multitude of resource-limited devices typically interconnected over Low Power and Lossy Networks (LLNs). Robust IP-based network routing among such constrained IoT devices can be effectively realized using the IPv6 Routing Protocol for LLN (RPL) which is an IETF-standardized protocol. The RPL design features a topology maintenance mechanism based on a version numbering system. However, such a design property makes it easy to initiate Version Number (VN) attacks targeting the stability, lifetime, and performance of RPL networks. Thus the wide deployment of RPL-based IoT networks would be hindered significantly unless internal routing attacks such as the VN attacks are efficiently addressed. In this research work, a lightweight and effective detection and mitigation solution against RPL VN attacks is introduced. With simple modifications to the RPL functionality, a collaborative and distributed security scheme is incorporated into the protocol design (referred to as CDRPL). As the experimental results indicated, it provides a secure and scalable solution enhancing the resilience of the protocol against simple and composite VN attacks in different experimental setups. CDRPL guaranteed fast and accurate attack detection as well as quick topology convergence upon any attack attempt. It also efficiently maintained network stability, control traffic overhead, QoS performance, and energy consumption during different scenarios of the VN attack. Compared to other similar approaches, CDRPL yields better performance results with lightweight node-local processing, no additional entities, and less communication overhead. |
first_indexed | 2024-04-12T01:30:03Z |
format | Article |
id | doaj.art-b9ba35f6028e43f7ae9e5a3c278f830c |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-04-12T01:30:03Z |
publishDate | 2022-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-b9ba35f6028e43f7ae9e5a3c278f830c2022-12-22T03:53:32ZengIEEEIEEE Access2169-35362022-01-011011111511113310.1109/ACCESS.2022.32154609923901A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT NetworksIbrahim S. Alsukayti0https://orcid.org/0000-0002-6925-598XAman Singh1https://orcid.org/0000-0001-6571-327XDepartment of Computer Science, College of Computer, Qassim University, Buraydah, Saudi ArabiaHigher Polytechnic School, Universidad Europea del Atlántico, Santander, SpainInternet of Things (IoT) systems incorporate a multitude of resource-limited devices typically interconnected over Low Power and Lossy Networks (LLNs). Robust IP-based network routing among such constrained IoT devices can be effectively realized using the IPv6 Routing Protocol for LLN (RPL) which is an IETF-standardized protocol. The RPL design features a topology maintenance mechanism based on a version numbering system. However, such a design property makes it easy to initiate Version Number (VN) attacks targeting the stability, lifetime, and performance of RPL networks. Thus the wide deployment of RPL-based IoT networks would be hindered significantly unless internal routing attacks such as the VN attacks are efficiently addressed. In this research work, a lightweight and effective detection and mitigation solution against RPL VN attacks is introduced. With simple modifications to the RPL functionality, a collaborative and distributed security scheme is incorporated into the protocol design (referred to as CDRPL). As the experimental results indicated, it provides a secure and scalable solution enhancing the resilience of the protocol against simple and composite VN attacks in different experimental setups. CDRPL guaranteed fast and accurate attack detection as well as quick topology convergence upon any attack attempt. It also efficiently maintained network stability, control traffic overhead, QoS performance, and energy consumption during different scenarios of the VN attack. Compared to other similar approaches, CDRPL yields better performance results with lightweight node-local processing, no additional entities, and less communication overhead.https://ieeexplore.ieee.org/document/9923901/Internet of Thingswireless sensor networksRPLnetwork security |
spellingShingle | Ibrahim S. Alsukayti Aman Singh A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks IEEE Access Internet of Things wireless sensor networks RPL network security |
title | A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks |
title_full | A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks |
title_fullStr | A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks |
title_full_unstemmed | A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks |
title_short | A Lightweight Scheme for Mitigating RPL Version Number Attacks in IoT Networks |
title_sort | lightweight scheme for mitigating rpl version number attacks in iot networks |
topic | Internet of Things wireless sensor networks RPL network security |
url | https://ieeexplore.ieee.org/document/9923901/ |
work_keys_str_mv | AT ibrahimsalsukayti alightweightschemeformitigatingrplversionnumberattacksiniotnetworks AT amansingh alightweightschemeformitigatingrplversionnumberattacksiniotnetworks AT ibrahimsalsukayti lightweightschemeformitigatingrplversionnumberattacksiniotnetworks AT amansingh lightweightschemeformitigatingrplversionnumberattacksiniotnetworks |