Quarantine-Based Mitigation of Local DoS Attacks in LLNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low Power and Lossy Networks (LLNs) face challenges such as lossy links, low bandwidth, and limited resources, making it difficult to manage and secure, especially with the complexity of large-scale IoT networks, where traditional approaches are inefficient and human processing is impractical.

Innovation Solution

Implementing a quarantine-based mitigation technique using a management device that alters the frequency hopping schedule of nodes under attack without revealing the changes to the attacker, ensuring unicast frequency hopping schedules are encrypted, and utilizing machine learning to dynamically compute quarantine periods and select nodes for quarantine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional routing and security management approaches are used in LLNs, then network operation can be maintained with simple protocols, but network security and management efficiency deteriorate due to the large number of nodes and complex conditions

Engineering Contradiction:
Improvenetwork management complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

A learning machine is introduced as an intermediary between network operators and the complex LLN environment. The LM automatically analyzes network conditions, predicts attacks, and makes routing/security decisions, eliminating the need for operators to manually manage complex networks while improving security through intelligent pattern recognition

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network system is equipped with a learning machine that enables it to autonomously monitor its own state, detect security threats, and adjust routing decisions without external intervention. This self-service capability allows the network to adapt to changing conditions and counter attacks in real-time

Inventive Principle:
Principle #25Self-service

2Reliability

If frequency hopping schedules are changed to counter DoS attacks, then network security improves, but the attacking node may learn the altered schedule and continue the attack

Engineering Contradiction:
Improvenetwork securityVSAvoidfrequency hopping schedule exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the frequency hopping schedule information from the broadcast traffic and places it exclusively in unicast traffic between the management device and individual nodes. This separation ensures that even if broadcast traffic is compromised, the actual frequency schedules remain secure and unknown to attackers

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The frequency hopping schedule information is segmented into individual unicast communications with each node rather than being transmitted collectively in broadcast traffic. This segmentation prevents an attacker from obtaining the complete schedule through broadcast interception

Inventive Principle:
Principle #1Segmentation

3Productivity

If machine learning is implemented to predict network behavior, then network management efficiency improves, but computational requirements and system complexity increase

Engineering Contradiction:
Improvenetwork management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The learning machine serves as an intermediary that handles the computational complexity of analyzing network patterns and predicting attacks, allowing the rest of the network to operate with simpler protocols while benefiting from intelligent decision-making capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2890173B1Quarantine-based mitigation of effects of a local doS attack
Publication Date: 2020.08.12 CISCO TECHNOLOGY INC
  • EP2890173B1 patent drawingFigure 1
  • EP2890173B1 patent drawingFigure 2
  • EP2890173B1 patent drawingFigure 3

AI summary

In one embodiment, techniques are shown and described relating to quarantine-based mitigation of effects of a local DoS attack. A management device may receive data indicating that one or more nodes in a shared-media communication network are under attack by an attacking node. The management device may then communicate a quarantine request packet to the one or more nodes under attack, the quarantine request packet providing instructions to the one or more nodes under attack to alter their frequency hopping schedule without allowing the attacking node to learn of the altered frequency hopping schedule.