Binary and Multi-Class Classification of RPL-Based Routing Attacks: An Experimental Study
Hemant Sharma, Gyan Singh Yadav · 2024
The Internet of Things (IoT) envisions billions to trillions of everyday objects that can be traced, addressed, and transmitted data. Typically, Low-power and Lossy Networks (LLNs) provide a mechanism for data exchange between IoT devices with limited power, processing capability, and memory. Routing over Low Power and Lossy Network (RPL) is a distance vector proactive routing protocol for LLN-based networks defined by the Internet Engineering Task Force (IETF). However, an RPL protocol is still vulnerable to a variety of routing attacks, which could disrupt the entire network architecture. As a security aspect of the RPL protocol against routing attacks, learning-based intrusion detection systems and classification have emerged as a promising research area, drawing the attention of several researchers. This paper contributes to this effort by conducting an experimental study on the classification of routing attacks using learning algorithms. A binary and multiclass dataset was created from the individual attack samples in the IoTR-DS dataset, and feature extraction via correlation enhanced the dataset with important features. To perform binary and multiclass classification, we used algorithms based on Machine Learning and Deep Learning, including Multi-layer Perceptron (MLP), Random Forest (RF), Support Vector Machine (SVM), K-Nearest Neighbor (KNN), and Decision Tree. The performance metrics used were recall, precision, f1-score, accuracy, and root mean square error. Random Forest (RF) achieves the highest accuracy for binary (98.05%) and multiclass (99.38%), with the lowest root mean square error (0.1396).