Routing Attack and Detection Methods in the RPL-based Internet of Things

Xinlong Wang, Wei Jun Yang, Chengqi Hou, Hongtao Luo · 2024

Routing Protocol for Low-power and Lossy Networks (RPL) was developed by the Internet Engineering Task Force (IETF) to address the specific needs of IoT networks characterized by low power, limited processing capabilities communication links. RPL aims to provide a scalable, efficient routing solution tailored to these constrained environments by optimizing energy usage and ensuring reliable communication among numerous IoT devices. Given its critical role in enabling effective communication within IoT networks, RPL is fundamental to the functionality and resilience of these systems. However, the design of RPL makes it susceptible to a range of sophisticated network attacks that can compromise network performance and security. Current datasets are unable to comprehensively cover the various attack types that RPL might be subjected to, and their data characteristics do not provide adequate support for anomaly detection algorithms. To bridge this gap, we have developed a specialized IoT dataset focusing on RPL, providing a comprehensive resource for training machine learning models to detect and analyze attacks targeting this protocol. Our study details the dataset’s simulation framework and feature extraction process, highlighting the impacts of three significant routing attacks: Black Hole attack, Hello Flooding attack, and Version Number attack. We evaluate five different machine learning models for anomaly detection using this dataset and find that all models effectively detect anomalous network traffic, with the Random Forest model achieving the highest accuracy.

Read the paper · More papers on PaperTik