{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,3]],"date-time":"2026-01-03T06:51:04Z","timestamp":1767423064616,"version":"3.44.0"},"reference-count":47,"publisher":"Association for Computing Machinery (ACM)","issue":"5","funder":[{"name":"PhD grant from the Conseil r\u00e9gional de Bretagne, France, and the Universit\u00e9 Bretagne Sud, Lorient, France"},{"name":"National Science Foundation in the United States, and by the GdR IASIS in France","award":["CNS-1902532"],"award-info":[{"award-number":["CNS-1902532"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,9,30]]},"abstract":"<jats:p>The rapid growth of Internet of Things (IoT) applications in various sectors has led to a significant increase in the number of IoT devices. This has led to the deployment of numerous IoT protocols to provide greater connectivity. However, this extensive adoption has also left them vulnerable to attack. In particular, attacks targeting wireless communication capabilities represent a significant threat. Such attacks exploit various vulnerabilities in the wireless connectivity unit, compromising its security. To counter this threat, this article proposes a Host Intrusion Detection System (HIDS) for detecting wireless attacks. Its components are customized to support IoT end-devices using low-GHz and sub-GHz data rate protocols. The HIDS deploys a hardware tracer to monitor microarchitecture and network metrics using hardware performance counters (HPCs). It performs monitoring of network and microarchitecture metrics for a 32-bit RISC-V-based wireless connectivity unit. The HIDS uses analysis and classification of monitored data for detecting memory corruption and jamming attacks. We evaluate the effectiveness of the HIDS in detecting packet injection and jamming attacks. Our Field?Programmable Gate Array (FPGA) implementation of HIDS has a logic overhead of about 14.30% and 22.89% of flip flops (FFs) and lookup tables (LUTs), respectively, compared to the CV32E40P baseline on an Arty A7 100T board. The design frequency and code size penalties are less than 1% for a RISC-V processor with a LoRaWAN protocol stack.<\/jats:p>","DOI":"10.1145\/3711833","type":"journal-article","created":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T06:24:16Z","timestamp":1736835856000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Diwall: A Lightweight Host Intrusion Detection System Against Jamming and Packet Injection Attacks"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5830-6756","authenticated-orcid":false,"given":"Mohamed","family":"El Bouazzati","sequence":"first","affiliation":[{"name":"Universit\u00e9 Bretagne Sud","place":["Lorient, France"]},{"name":"UMR CNRS 6285, Lab-STICC","place":["Lorient, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4686-6435","authenticated-orcid":false,"given":"Philippe","family":"Tanguy","sequence":"additional","affiliation":[{"name":"Universite Bretagne Sud","place":["Lorient, France"]},{"name":"UMR CNRS 6285, Lab-STICC","place":["Lorient, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9528-5277","authenticated-orcid":false,"given":"Guy","family":"Gogniat","sequence":"additional","affiliation":[{"name":"Universite Bretagne Sud","place":["Lorient, France"]},{"name":"UMR CNRS 6285, Lab-STICC","place":["Lorient, France"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0591-7566","authenticated-orcid":false,"given":"Russell","family":"Tessier","sequence":"additional","affiliation":[{"name":"University of Massachusetts","place":["Amherst, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,9,12]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"Number of Connected IoT Devices","author":"Analytics IoT","year":"2024","unstructured":"IoT Analytics. 2024. Number of Connected IoT Devices. Retrieved September 17, 2024 from https:\/\/iot-analytics.com\/number-connected-iot-devices\/"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241275"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394497"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3144457.3144478"},{"volume-title":"BLEEDINGBIT Vulnerability Analysis","year":"2019","key":"e_1_3_2_6_2","unstructured":"Armis. 2019. BLEEDINGBIT Vulnerability Analysis. Retrieved September 19, 2024 from https:\/\/www.armis.com\/research\/bleedingbit\/"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-58387-6_14"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/DDECS57882.2023.10139718"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/NCA51143.2020.9306726"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.050113.00191"},{"key":"e_1_3_2_11_2","volume-title":"Offensive and Defensive Approaches for Wireless Communication Protocols Security in IoT","author":"Cayre Romain","year":"2022","unstructured":"Romain Cayre. 2022. Offensive and Defensive Approaches for Wireless Communication Protocols Security in IoT. Ph.D. Dissertation. INSA Toulouse, Toulouse, France. https:\/\/tel.archives-ouvertes.fr\/tel-03841305"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00050"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00049"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00021"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2970501"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3441458"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399423"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3583137"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/VTCSpring.2019.8746374"},{"key":"e_1_3_2_20_2","volume-title":"CC1352R: Multi-band Wireless SoC","author":"Instruments Texas","year":"2023","unstructured":"Texas Instruments. 2023. CC1352R: Multi-band Wireless SoC. Retrieved September 17, 2024 from https:\/\/www.ti.com\/product\/CC1352R"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3403943"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2512494"},{"key":"e_1_3_2_23_2","volume-title":"AMNESIA:33, How Embedded TCP\/IP Stacks Breed Critical Vulnerabilities","author":"Labs Forescout Research","year":"2020","unstructured":"Forescout Research Labs. 2020. AMNESIA:33, How Embedded TCP\/IP Stacks Breed Critical Vulnerabilities. Retrieved September 17, 2024 from https:\/\/i.blackhat.com\/eu-20\/Wednesday\/eu-20-dosSantos-How-Embedded-TCPIP-Stacks-Breed-Critical-Vulnerabilities-wp.pdf"},{"key":"e_1_3_2_24_2","volume-title":"Jamming on LoRaWAN Networks: From Modelling to Detection","author":"Bolivar Ivan Marino Martinez","year":"2021","unstructured":"Ivan Marino Martinez Bolivar. 2021. Jamming on LoRaWAN Networks: From Modelling to Detection. Ph.D. Dissertation. Institut National des Sciences Appliqu\u00e9es de Rennes, Rennes, France. https:\/\/theses.hal.science\/tel-03196484"},{"key":"e_1_3_2_25_2","volume-title":"LimeSDR Mini RX & TX 10MHz - 3.5GHz Full-duplex","author":"Microsystems Lime","year":"2017","unstructured":"Lime Microsystems. 2017. LimeSDR Mini RX & TX 10MHz - 3.5GHz Full-duplex. Retrieved September 17, 2024 from https:\/\/www.passion-radio.fr\/emetteur-sdr\/limesdr-mini-667.html"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2009.090404"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3214292.3214293"},{"volume-title":"CV32E40P User Manual","year":"2024","key":"e_1_3_2_28_2","unstructured":"OpenHWGroup. 2024. CV32E40P User Manual. Retrieved September 19, 2024 from https:\/\/docs.openhwgroup.org\/projects\/cv32e40p-user-manual\/en\/latest\/"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.3390\/s18061691"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3159185"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2013.04.014"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3543805"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.3390\/s22093127"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11036-023-02223-6"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-019-01502-z"},{"volume-title":"LoRaMac-node Repository","year":"2013","key":"e_1_3_2_36_2","unstructured":"Semtech. 2013. LoRaMac-node Repository. Retrieved August 30, 2023 from https:\/\/github.com\/Lora-net\/LoRaMac-node"},{"volume-title":"Worldwide Annual Internet of Things Attacks","year":"2023","key":"e_1_3_2_37_2","unstructured":"Statista. 2023. Worldwide Annual Internet of Things Attacks. Retrieved September 17, 2024 from https:\/\/www.statista.com\/statistics\/1377569\/worldwide-annual-internet-of-things-attacks\/"},{"volume-title":"STM32WL55CC: Wireless System-on-chip (SoC)","year":"2023","key":"e_1_3_2_38_2","unstructured":"STMicroelectronics. 2023. STM32WL55CC: Wireless System-on-chip (SoC). Retrieved September 17, 2024 from https:\/\/www.st.com\/en\/microcontrollers-microprocessors\/stm32wl55cc.html"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/1824766.1824772"},{"key":"e_1_3_2_40_2","volume-title":"ESP32-H2: Wi-Fi and Bluetooth LE SoC","author":"Systems Espressif","year":"2023","unstructured":"Espressif Systems. 2023. ESP32-H2: Wi-Fi and Bluetooth LE SoC. Retrieved September 17, 2024 from https:\/\/www.espressif.com\/en\/products\/socs\/esp32-h2"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766455"},{"key":"e_1_3_2_42_2","volume-title":"LoRaDawn","author":"Team Tencent Blade","year":"2020","unstructured":"Tencent Blade Team. 2020. LoRaDawn. Retrieved September 19, 2024 from https:\/\/github.com\/Lora-net\/LoRaMac-node\/security"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3586209.3591395"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3127681"},{"key":"e_1_3_2_45_2","first-page":"397","volume-title":"Proceedings of the 23rd USENIX International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920)","author":"Wu Jianliang","year":"2020","unstructured":"Jianliang Wu, Yuhong Nan, Vireshwar Kumar, Mathias Payer, and Dongyan Xu. 2020. BlueShield: Detecting spoofing attacks in Bluetooth low energy networks. In Proceedings of the 23rd USENIX International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920). 397\u2013411. https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/wu"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3396870.3400010"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.02.009"},{"key":"e_1_3_2_48_2","first-page":"18","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920)","author":"Zhang Yue","year":"2020","unstructured":"Yue Zhang, Jian Weng, Rajib Dey, Yier Jin, Zhiqiang Lin, and Xinwen Fu. 2020. Breaking secure pairing of Bluetooth low energy using downgrade attacks. In Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920). Article 3, 18 pages."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711833","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,12]],"date-time":"2025-09-12T11:44:26Z","timestamp":1757677466000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711833"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,12]]},"references-count":47,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9,30]]}},"alternative-id":["10.1145\/3711833"],"URL":"https:\/\/doi.org\/10.1145\/3711833","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2025,9,12]]},"assertion":[{"value":"2024-02-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-13","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}