SPRINKLER: A Multi-RPL Man-in-the-Middle Identification Scheme in IoT Networks
Aviram Zilberman, Amit Z. Dvir, Ariel Stulman · IEEE Transactions on Mobile Computing · 2024
Cyber-threat protection is one of the most challenging research branches of Internet-of-Things (iot). With the exponential increase of tiny connected devices, the battle between friend and foe intensifies. Unfortunately,iotdevices offer very limited security features, laying themselves wide open to new attacks, inhibiting the expected global adoption ofiottechnologies. Moreover, existing prevention and mitigation techniques and intrusion detection systems handle attack anomalies rather than the attack itself while using a significant amount of the network resources.rpl, the de-facto routing protocol foriot, proposes minimal security features that cannot handle internal attacks. Hence, in this paper, we proposesprinkler, which identifies the specificthingthat is under attack by an adversarial Man-in-The-Middle.sprinkleruses the multi-instance feature ofrplto identify the adversary. The proposed solution adheres to two basic principles: it only uses pre-existing standard routing protocols and does not rely on a centralized or trusted third-party node such as a certificate authority. All information must be gleaned by each node using only primitives that already exist in the underlying communication protocol, which excludes any training dataset. Simulations show thatsprinkleradds minimal maintenance and energy expenditure while pinpointing deterministically the attacker in the network. In particular,sprinklerhas a message delivery rate and detection rate of 100%.