A4 Vertaisarvioitu artikkeli konferenssijulkaisussa

Distributed Internal Anomaly Detection System for Internet-of-Things




TekijätThanigaivelan NK, Nigussie E, Kanth RK, Virtanen S, Isoaho J

ToimittajaIEEE

Konferenssin vakiintunut nimiIEEE Annual Consumer Communications and Networking Conference

KustannuspaikkaNEW YORK, NY

Julkaisuvuosi2016

Kokoomateoksen nimi2016 13th IEEE Annual Consumer Communications & Networking Conference (CCNC)

Tietokannassa oleva lehden nimi2016 13TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC)

Sarjan nimiIEEE Consumer Communications & Networking Conference

Numero sarjassa13

Aloitussivu319

Lopetussivu320

Sivujen määrä2

ISBN978-1-4673-9291-4

eISBN978-1-4673-9292-1

ISSN2331-9860

DOIhttps://doi.org/10.1109/CCNC.2016.7444797


Tiivistelmä
We present overview of a distributed internal anomaly detection system for Internet-of-things. In the detection system, each node monitors its neighbors and if abnormal behavior is detected, the monitoring node will block the packets from the abnormally behaving node at the data link layer and reports to its parent node. The reporting propagates from child to parent nodes until it reaches the root. A novel control message, distress propagation object (DPO), is devised to report the anomaly to the subsequent parents and ultimately the edge-router. The DPO message is integrated to routing protocol for low-power and lossy networks (RPL). The system has configurable profile settings and it is able to learn and differentiate the nodes' normal and suspicious activities without a need for prior knowledge. It has different subsystems and operation phases at data link and network layers, which share a common repository in a node. The system uses network fingerprinting to be aware of changes in network topology and nodes' positions without any assistance from a positioning system.



Last updated on 2024-26-11 at 20:12