SVELTE: Real-time intrusion detection in the Internet of Things

被引:549
作者
Raza, Shahid [1 ]
Wallgren, Linus [1 ]
Voigt, Thiemo [1 ,2 ]
机构
[1] SICS Swedish ICT, Stockholm, Sweden
[2] Uppsala Univ, Dept Informat Technol, Uppsala, Sweden
关键词
Intrusion detection; Internet of Things; 6LoWPAN; RPL; IPv6; Security; Sensor networks; WIRELESS; LIGHTWEIGHT;
D O I
10.1016/j.adhoc.2013.04.014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the Internet of Things (IoT), resource-constrained things are connected to the unreliable and untrusted Internet via IPv6 and 6LoWPAN networks. Even when they are secured with encryption and authentication, these things are exposed both to wireless attacks from inside the 6LoWPAN network and from the Internet. Since these attacks may succeed, Intrusion Detection Systems (IDS) are necessary. Currently, there are no IDSs that meet the requirements of the IPv6-connected IoT since the available approaches are either customized for Wireless Sensor Networks (WSN) or for the conventional Internet. In this paper we design, implement, and evaluate a novel intrusion detection system for the IoT that we call SVELTE. In our implementation and evaluation we primarily target routing attacks such as spoofed or altered information, sinkhole, and selective-forwarding. However, our approach can be extended to detect other attacks. We implement SVELTE in the Contiki OS and thoroughly evaluate it. Our evaluation shows that in the simulated scenarios, SVELTE detects all malicious nodes that launch our implemented sinkhole and/or selective forwarding attacks. However, the true positive rate is not 100%, i.e., we have some false alarms during the detection of malicious nodes. Also, SVELTE's overhead is small enough to deploy it on constrained nodes with limited energy and memory capacity. (C) 2013 Elsevier B.V. All rights reserved.
引用
收藏
页码:2661 / 2674
页数:14
相关论文
共 35 条
[31]  
Raza S., 2011, 2011 INT C DISTR COM, P1, DOI 10.1109/DCOSS.2011.5982177
[32]   Secure communication for the Internet of Things-a comparison of link-layer security and IPsec for 6LoWPAN [J].
Raza, Shahid ;
Duquennoy, Simon ;
Hoglund, Joel ;
Roedig, Utz ;
Voigt, Thiemo .
SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (12) :2654-2668
[33]  
Roman R, 2006, CONSUM COMM NETWORK, P640
[34]  
Rong CM, 2011, COMM COM INF SC, V187, P116
[35]  
Wang Weichao., 2004, P ACM WORKSHOP WIREL, P51