ML Based Rank Attack Detection for Smart Hospital Infrastructure
29
for wide areas [7]. This capability made the birth to the notion of smart infrastructures such as smart metering systems, smart grid or smart hospitals. In such
infrastructures, end devices collecting data are connected to intermediate nodes
that forward data in order to reach border routers using routing protocols. These
end nodes are in general limited in terms of computational resources, battery and
memory capacities. Also, their number is growing exponentially. Therefore, new
protocols are proposed under the IoT paradigm to optimize energy consumption
and computations. Two of these protocols are considered the de facto protocols
for the Internet of Things (IoT): RPL (Routing Protocol for Low Power Lossy
Network) and 6LoWPAN (IPv6 over Low Power Wireless Private Area Network).
These protocols are designed for constrained devices in recent IoT applications.
Routing is a key part of the IPv6 stack that remains to be specified for 6LowPan networks [6]. RPL provides a mechanism whereby multipoint-to-point traffic
from devices inside the Low-Power and Lossy-Networks (LLNs) towards a central
control point as well as point-to-multipoint traffic from the central control point
to the device inside the LLN are supported [8,9]. RPL involves many concepts
that make it a flexible protocol, but also rather complex [10]:
• DODAG (Destination Oriented Directed Acyclic Graph): a topology similar
to a tree to optimize routes between sink and other nodes for both the collect
and distribute data traffics. Each node within the network has an assigned
rank, which increases as the teals move away from the root node. The nodes
resend packets using the lowest range as the route selection criteria.
• DIS (DODAG Information Solicitation): used to solicit a DODAG information
object from RPL nodes.
• DIO (DODAG Information Object): used to construct, maintain the DODAG
and to periodically refresh the information of the nodes on the topology of
the network.
• DAO (DODAG Advertisment Object): used by nodes to propagate destination information upward along the DODAG in order to update the information of their parents.
With the enormous number of devices that are now connected to the Internet,
a new solution was proposed: 6LowPan a lightweight protocol that defines how
to run IP version 6 (IPv6) over low data rate, low power, small footprint radio
networks as typified by the IEEE 802.15.4 radio [11]. In smart infrastructures,
the huge amount of sensitive data exchanged among these modules and throughout radio interfaces need to be protected. Therefore, detecting any network or
device breach becomes a high priority challenge for researchers due to resource
constraints for devices (low processing power, battery power and memory size).
Rank attack is one of the most known RPL attacks where the attacker attracts
other nodes to establish routes through it by advertising false rank. This way,
intruders collect all the data that pass in the network [12].
For this reason, developing specific security solutions for IoT is essential to let
users catch all opportunities it offers. One of defense lines designed for detecting
attackers is Intrusion Detection Systems [13] (IDS). In this paper, we propose a
29
for wide areas [7]. This capability made the birth to the notion of smart infrastructures such as smart metering systems, smart grid or smart hospitals. In such
infrastructures, end devices collecting data are connected to intermediate nodes
that forward data in order to reach border routers using routing protocols. These
end nodes are in general limited in terms of computational resources, battery and
memory capacities. Also, their number is growing exponentially. Therefore, new
protocols are proposed under the IoT paradigm to optimize energy consumption
and computations. Two of these protocols are considered the de facto protocols
for the Internet of Things (IoT): RPL (Routing Protocol for Low Power Lossy
Network) and 6LoWPAN (IPv6 over Low Power Wireless Private Area Network).
These protocols are designed for constrained devices in recent IoT applications.
Routing is a key part of the IPv6 stack that remains to be specified for 6LowPan networks [6]. RPL provides a mechanism whereby multipoint-to-point traffic
from devices inside the Low-Power and Lossy-Networks (LLNs) towards a central
control point as well as point-to-multipoint traffic from the central control point
to the device inside the LLN are supported [8,9]. RPL involves many concepts
that make it a flexible protocol, but also rather complex [10]:
• DODAG (Destination Oriented Directed Acyclic Graph): a topology similar
to a tree to optimize routes between sink and other nodes for both the collect
and distribute data traffics. Each node within the network has an assigned
rank, which increases as the teals move away from the root node. The nodes
resend packets using the lowest range as the route selection criteria.
• DIS (DODAG Information Solicitation): used to solicit a DODAG information
object from RPL nodes.
• DIO (DODAG Information Object): used to construct, maintain the DODAG
and to periodically refresh the information of the nodes on the topology of
the network.
• DAO (DODAG Advertisment Object): used by nodes to propagate destination information upward along the DODAG in order to update the information of their parents.
With the enormous number of devices that are now connected to the Internet,
a new solution was proposed: 6LowPan a lightweight protocol that defines how
to run IP version 6 (IPv6) over low data rate, low power, small footprint radio
networks as typified by the IEEE 802.15.4 radio [11]. In smart infrastructures,
the huge amount of sensitive data exchanged among these modules and throughout radio interfaces need to be protected. Therefore, detecting any network or
device breach becomes a high priority challenge for researchers due to resource
constraints for devices (low processing power, battery power and memory size).
Rank attack is one of the most known RPL attacks where the attacker attracts
other nodes to establish routes through it by advertising false rank. This way,
intruders collect all the data that pass in the network [12].
For this reason, developing specific security solutions for IoT is essential to let
users catch all opportunities it offers. One of defense lines designed for detecting
attackers is Intrusion Detection Systems [13] (IDS). In this paper, we propose a
