Network Path Attack Detectability Metrics for LLN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low Power and Lossy Networks (LLNs) face challenges in detecting Denial of Service (DoS) attacks due to dynamic conditions and limited resources, making it difficult to determine when an attack is underway without triggering false positives or missing attacks, and the sensitivity level of attack detection mechanisms needs to be carefully balanced.
Innovation Solution
The implementation of attack detectability metrics from nodes along a network path to compute a path attack detectability value, which is used to adjust routing paths based on a network policy, ensuring that routing decisions prioritize attack detectability, thereby guaranteeing a predefined success rate for attack detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If attack detection sensitivity is increased to improve detection rate, then attack detection capability is improved, but false positives increase and resource consumption increases
Solution Approach 1:
The patent introduces attack detectability metrics as an intermediary measure that quantifies the relationship between detection sensitivity and false positive rates. These metrics serve as a mediator to optimize the balance between detection capability and false alarm generation, allowing the system to operate at an optimal sensitivity level without excessive false positives.
Solution Approach 2:
The patent changes the parameter of detection sensitivity by using attack detectability metrics to dynamically adjust the sensitivity level. Instead of operating at maximum sensitivity, the system adjusts parameters based on metric values to achieve optimal detection performance while minimizing false positives and resource consumption.
2Reliability
If attack detection sensitivity is increased to improve detection rate, then attack detection capability is improved, but resource consumption increases
Solution Approach 1:
The patent changes the operational parameters of attack detection by introducing detectability metrics that guide the adjustment of detection sensitivity. This allows the system to operate at optimized parameter settings that reduce resource consumption while maintaining adequate detection capability, rather than continuously operating at maximum sensitivity.
Solution Approach 2:
The patent applies partial action by using attack detectability metrics to determine the appropriate level of detection effort. Instead of always applying maximum detection resources, the system applies partial detection action based on metric values, reducing resource consumption when high detection sensitivity is not necessary.
3Reliability
If routing decisions prioritize attack detectability, then attack detection reliability is improved, but routing flexibility is reduced
Solution Approach 1:
The patent changes the routing decision parameters by incorporating attack detectability metrics as an additional criterion. This allows the routing system to adapt its behavior based on detection reliability requirements, selecting paths with higher detectability when needed while maintaining flexibility to use other routing criteria when detection concerns are less critical.
Data Source
AI summary
In one embodiment, attack detectability metrics are received from nodes along a path in a network. The attack detectability metrics from the nodes along the path are used to compute a path attack detectability value. A determination is made as to whether the path attack detectability value satisfies a network policy and one or more routing paths in the network are adjusted based on the path attack detectability value not satisfying the network policy.


