Safeguarding IoT Systems: Novel Authentication Method to Counteract Sybil and Flood Attacks
Iain Baird, Baraq Ghaleb, Isam Wadhaj, Gordon Russell, William Johnston Buchanan · 2024
This paper introduces an innovative strategy for countering Sybil and DODAG Information Solicitation (DIS) flood attacks within lightweight Internet of Things (IoT) networks. The proposed method combines a one-way hash chain with a Bloom filter, leveraging the probabilistic and space-efficient attributes of Bloom filters for swift query responses and efficient identity verification across extensive data sets. Sybil attacks, characterized by the creation of multiple counterfeit identities to gain control over a network, and flood attacks, which overwhelm a network with excessive traffic, are significant threats addressed by this approach. Particularly in Routing Protocol for Low Power and Lossy Networks (RPL), Sybil attacks pose a challenge to threshold-based protection against flood attacks by frequently altering node identities. To mitigate these risks, the suggested solution advocates for each node in the network to generate a one-way series of hashes. The root of this hash chain is then employed for identifying and filtering legitimate traffic using the Bloom filter. This method aims to enhance security in lightweight IoT networks by thwarting Sybil and flood attacks through a combination of one-way hash chains and Bloom filters.