ML Based Rank Attack Detection for Smart Hospital Infrastructure
31
Fig. 1. Smart hospital assets.
2 Related Work
RPL protocol security especially in the healthcare domain is a crucial aspect for
preserving personnel data. Nodes rank is an important parameter for an RPL
network. It can be used for route optimization, loop prevention, and topology
maintenance. In fact, the rank attack can decrease the network performance in
terms of packet delivery rate (PDR) to almost 60% [23]. There were different
proposed solutions to detect and mitigate RPL attacks such as rank authentication mechanism to avoid false announced ranks by using cryptography technique
which was proposed in [24]. However, this technique is not very efficient because
of its high computational cost and energy consumption. Authors in [25] propose
a monitoring node (MN) based scheme but it is also not efficient because using a
large network of MNs causes a communication overhead. In [26], authors propose
the IDS called “SVELTE” that can only be used for detection of simple rank
attack and has high false alarm rate. A host-based IDS was proposed in [27]. The
IDS uses a probabilistic scheme but it is discouraged by RFC6550 for resource
constrained networks. Routing Choice “RC” was proposed by Zhag et al. [28]. It
is not directly related to the rank attack but it is based on false preferred parent
selection. It has a high communication overhead in RPL networks. Trusted platform module (TPM) was proposed by Seeber et al. [29]. It introduces an overlay
network of TPM nodes for detection of network attacks. SecureRPL (SRPL)
[30] technique prevents RPL network from Rank attack, however it is characterized by a high energy consumption. Therefore, anomaly based solutions using
machine learning permit a more efficient detection. Authors of [22] compared
several unsupervised machine learning approaches based on local outlier factor,
near neighbors, Mahalanobis distance and SVMs for intrusion detection. Their
experiments showed that O-SVM is the most appropriate technique to detect
selective forwarding and jamming attacks. Actually, we rely on these results in
our choice of O-SVM.
31
Fig. 1. Smart hospital assets.
2 Related Work
RPL protocol security especially in the healthcare domain is a crucial aspect for
preserving personnel data. Nodes rank is an important parameter for an RPL
network. It can be used for route optimization, loop prevention, and topology
maintenance. In fact, the rank attack can decrease the network performance in
terms of packet delivery rate (PDR) to almost 60% [23]. There were different
proposed solutions to detect and mitigate RPL attacks such as rank authentication mechanism to avoid false announced ranks by using cryptography technique
which was proposed in [24]. However, this technique is not very efficient because
of its high computational cost and energy consumption. Authors in [25] propose
a monitoring node (MN) based scheme but it is also not efficient because using a
large network of MNs causes a communication overhead. In [26], authors propose
the IDS called “SVELTE” that can only be used for detection of simple rank
attack and has high false alarm rate. A host-based IDS was proposed in [27]. The
IDS uses a probabilistic scheme but it is discouraged by RFC6550 for resource
constrained networks. Routing Choice “RC” was proposed by Zhag et al. [28]. It
is not directly related to the rank attack but it is based on false preferred parent
selection. It has a high communication overhead in RPL networks. Trusted platform module (TPM) was proposed by Seeber et al. [29]. It introduces an overlay
network of TPM nodes for detection of network attacks. SecureRPL (SRPL)
[30] technique prevents RPL network from Rank attack, however it is characterized by a high energy consumption. Therefore, anomaly based solutions using
machine learning permit a more efficient detection. Authors of [22] compared
several unsupervised machine learning approaches based on local outlier factor,
near neighbors, Mahalanobis distance and SVMs for intrusion detection. Their
experiments showed that O-SVM is the most appropriate technique to detect
selective forwarding and jamming attacks. Actually, we rely on these results in
our choice of O-SVM.
