The growing adoption of LoRaWAN for large-scale IoT deployments makes these networks an attractive target for cyber-attacks. While anomalous behaviours might not be difficult to detect, spotting the physical location of attackers remains a major challenge, especially when attacks originate from mobile, low-cost, or self-built devices. This work introduces an integrated cyber-physical security framework that couples anomaly detection with fine-grained wireless localization to identify and track malicious nodes. First, a supervised anomaly-based algorithm uses features extracted from network telemetry data to detect anomalies. Second, a localization engine leverages TDoA and nonlinear least squares estimation to scan the affected area and locate the attacker, even in case of the attacker movement. We validate the proposed architecture, attack model, detection pipeline, and localization strategy through experimental evaluation. For this purpose, we implemented a novel DoS attack, the DevNonce saturation attack, which exploits the join procedure in OTAA-enabled devices to exhaust nonce space and prevent legitimate nodes from connecting. Experimental results demonstrate the accuracy, feasibility, and applicability of the proposed framework to real LoRaWAN environments, and have also led to the discovery of a novel vulnerability affecting ChirpStack.

Addressing Cybersecurity and Nodes Localization on LoRaWAN Networks

Noshadi A.;Amangeldiyeva Z.;Cambiaso E.;Zappatore S.;Patrone F.
2026-01-01

Abstract

The growing adoption of LoRaWAN for large-scale IoT deployments makes these networks an attractive target for cyber-attacks. While anomalous behaviours might not be difficult to detect, spotting the physical location of attackers remains a major challenge, especially when attacks originate from mobile, low-cost, or self-built devices. This work introduces an integrated cyber-physical security framework that couples anomaly detection with fine-grained wireless localization to identify and track malicious nodes. First, a supervised anomaly-based algorithm uses features extracted from network telemetry data to detect anomalies. Second, a localization engine leverages TDoA and nonlinear least squares estimation to scan the affected area and locate the attacker, even in case of the attacker movement. We validate the proposed architecture, attack model, detection pipeline, and localization strategy through experimental evaluation. For this purpose, we implemented a novel DoS attack, the DevNonce saturation attack, which exploits the join procedure in OTAA-enabled devices to exhaust nonce space and prevent legitimate nodes from connecting. Experimental results demonstrate the accuracy, feasibility, and applicability of the proposed framework to real LoRaWAN environments, and have also led to the discovery of a novel vulnerability affecting ChirpStack.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1313976
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact