Detecting and mitigating DIS attack in RPL-based network
Alaa Eddine Khalfoune, Rachid Beghdad · EDPACS · 2025
The Routing Protocol for Low-Power and Lossy Networks (RPL) is among the most used protocol in the Internet of Things. In RPL, the network is established by creating a tree topology called Destination Oriented Directed Acyclic Graphs (DODAG), However, RPL-based networks stability is vulnerable to different attacks such as DODAG Information Solicitation (DIS) flooding attack. In this attack, a malicious node sends large number of DIS messages in the neighborhood, which compels the receiver nodes to exchange more control messages, causing resources deplete. Unfortunately, RPL has no means to detect or mitigate DIS flooding attacks. In this paper, we present a novel Adaptive Threshold Mechanism to mitigate DIS attack called (ATM-RPL). In the proposed approach, the number of exchanged control messages is used to determine the network state which in turn used to calculate a dynamic threshold. ATM-RPL proved its effectiveness and superiority over similar proposed mechanism in terms of false positive, construction time, power consumption, and packet delivery ratio.