← 返回
光伏发电技术 储能系统 ★ 4.0

一种缓解基于RPL的物联网网络中新泛洪攻击的简单方法

A Simple Approach for Mitigating a New Flooding Attack in RPL-Based IoT Networks

作者 Mehdi Rouissat · Ibrahim S. Alsukayti · Mohammed Belkheir · Mohammed Alreshoodi · Allel Mokaddem · Djamila Ziani
期刊 IEEE Access
出版日期 2025年1月
技术分类 光伏发电技术
技术标签 储能系统
相关度评分 ★★★★ 4.0 / 5.0
关键词 物联网网络安全 RPL协议 泛洪攻击 DAOF攻击 DAOF - SRPL解决方案
语言:

中文摘要

物联网设备在各类智能应用中的广泛部署使其网络安全成为关键需求。然而,即使对于标准化的低功耗有损网络IPv6路由协议(RPL),其安全支持仍面临挑战,尤其易受内部路由攻击。本文提出一种新型泛洪攻击——目标通告对象泛洪(DAOF)攻击,利用DAO消息制造冗余路由流量,导致控制消息过度传输。实验表明,DAOF可使网络开销增加逾65%,能耗平均上升36%,时延增加150%。为此,本文提出轻量级防御方案DAOF-SRPL,通过节点间简单协作和协议内修改有效抵御该攻击。相比受攻击的RPL,DAOF-SRPL使控制消息发送率降低80%以上,同时保持能效、低时延及相近的包投递率。

English Abstract

The growing deployment of Internet of Things (IoT) devices in diverse daily-life smart applications makes the security of IoT networks a critical requirement. However, efficient support of network security remains challenging even for a standardized IoT network protocol such as the IPv6 Routing Protocol for Low Power and Lossy Networks (RPL). It incorporates limited protection from external security attacks but stays considerably vulnerable to internal routing attacks. The inherent design of RPL, particularly its topology establishment and maintenance mechanism, makes it easy to initiate more damaging attacks such as flooding attacks. Given the constrained characteristics of IoT devices, flooding IoT networks can easily lead to resource exhaustion and network performance degradation. This paper introduces a new variant of the flooding attack namely the Destination Advertisement Object Flooding (DAOF) attack. It is based on using routing communications, particularly the DAO messages, to disseminate unnecessary routing traffic which instigate excessive transmissions of control messages across the network. As demonstrated by the experimental results of this study, the DAOF attack can increase network overhead by more than 65% even in a relatively small-scale setup. Additionally, it can notably lead to high energy consumption with an average increase of 36% and low QoS performance with an average latency increase of 150%. For effective mitigation of the DAOF attack, a new lightweight solution based on a simple collaboration among RPL nodes is presented in this paper. It is referred to as DAOF-Secure RPL (DAOF-SRPL). It is based on simple in-protocol modifications to provide RPL with effective security support against the DAOF attack. In contrast to RPL in the attack scenarios, DAOF-SRPL achieved a reduction of over 80% in the total transmission rates of control messages. Meanwhile, it was able to maintain energy consumption and latency at minimal levels while preserving the same PDR results.
S

SunView 深度解读

该RPL网络安全防护技术对阳光电源分布式能源物联网系统具有重要应用价值。在PowerTitan大型储能系统和iSolarCloud云平台中,大量储能变流器、光伏逆变器通过低功耗物联网协议实现组网通信和数据采集。DAOF-SRPL的轻量级防御方案可直接应用于ST系列储能变流器和SG系列逆变器的通信模块,有效抵御内部路由攻击导致的控制消息泛洪。其降低80%控制消息、减少36%能耗的效果,可显著提升分布式电站通信可靠性,降低边缘设备功耗,增强智能运维系统的网络安全防护能力,为构建安全可信的新能源物联网提供技术支撑。