214
Internet of Things (IoT)
11.2 Literature Review
If we consider the terms of the Internet facility and advancement of today, it was not difficult to make different computers communicate with each other and make them perform
simple operations such as sending and receiving e-mails. We can think about interconnecting people, information, and systems. The emergence of miniaturized systems that are
equally powerful, which can act independently and smartly due to the advanced software,
empowers the concept that in many of the scenarios there might be implanted or linked
processors responsible for its functioning.
In the IoT, resource-restrained elements are connected to the untrustworthy and undependable Internet via IPv6 and 6LoWPAN networks [1]. The wireless intrusions from both
the Internet and the internal part of 6LoWPAN network are what make these susceptible to both external and internal attacks. The requirement of intrusion detection systems
(IDSs) is considered to be necessary due to the probability of occurrence of these attacks.
Presently, due to the limitation of IDS approaches, which are being designed only for
wireless sensor networks (WSNs) or traditional Internet, there is no IDS that can live up to
the necessities of the IoT connected to IPv6.
In the work of Raza et al. [1], an innovative IDS for the IoT called SVELTE has been
blueprinted, enacted, and assessed. In the execution and evaluation, the authors have fundamentally focused on attacks on the routing like imitation or alteration of information,
sinkhole, and selective forwarding. However, they claim to extend the applicability of their
designed system to detect other intrusions. They implement SVELTE in the Contiki OS
and assess it profoundly. Their assessment depicts that in the simulated cases SVELTE
spots all harmful nodes that initiate the executed sinkhole and/or forwarding intrusions
with an accuracy rate of <100%, because of certain false notifications during the spotting.
Figure 11.2 represents a general summary of the IDS, one of whose prime goals is that IDS
should be lightweight and compatible with the processing abilities of the nodes. They also
have enacted the idea of a distributed mini-firewall to secure the 6LoWPAN networks
from the unauthorized users at a global level. They implement SVELTE in the Contiki
operating system.
Border-router
Network stack
TCP/TLS
IPv6
6LoWPAN
IEEE 802.15.4
UDP/DTLS
IDS-modules
• Packet loss
• Firewall notification
• 6mapper client
• 6mapper
• Spoofing or alteration
detection
• Node availability
• Graph validity
• End-to-end packet loss
• Mini-firewall
IPSEC
RPL
FIGURE 11.2
Illustration of IoT where IDS modules are kept in 6BR and in the separate end points.
Précédent

- 239/358

Suivant