The inherent support for multiple instances in the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) enables concurrent operation of diverse Internet of Things (IoT) applications. However, the lack of a robust secure mechanism ultimately makes RPL vulnerable to intrusions. Considerable efforts have been dedicated to developing Intrusion Detection Systems (IDSs) to counter RPL attacks, which affect traffic patterns differently, resulting in reduced performance across diverse RPL scenarios. To address this, we propose a transfer learning-based IDS designed to operate effectively across multiple instances. The proposed IDS is applied in networks featuring two RPL instances: i) a regular instance, composed only of regular nodes, and ii) a monitoring instance, which includes monitoring nodes to collect local data to improve detection accuracy. The IDS is evaluated on four well-known RPL attacks: decreased rank, worst parent, DIS flooding, and increased version. The results show that proposed IDS achieves promising detection accuracy, demonstrating its adaptability and robustness across multiple instances.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Transfer Learning-Based Intrusion Detection for Multi-instance RPL Networks in IoT

  • Ali Deveci,
  • Sevil Sen,
  • Selim Yilmaz

摘要

The inherent support for multiple instances in the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) enables concurrent operation of diverse Internet of Things (IoT) applications. However, the lack of a robust secure mechanism ultimately makes RPL vulnerable to intrusions. Considerable efforts have been dedicated to developing Intrusion Detection Systems (IDSs) to counter RPL attacks, which affect traffic patterns differently, resulting in reduced performance across diverse RPL scenarios. To address this, we propose a transfer learning-based IDS designed to operate effectively across multiple instances. The proposed IDS is applied in networks featuring two RPL instances: i) a regular instance, composed only of regular nodes, and ii) a monitoring instance, which includes monitoring nodes to collect local data to improve detection accuracy. The IDS is evaluated on four well-known RPL attacks: decreased rank, worst parent, DIS flooding, and increased version. The results show that proposed IDS achieves promising detection accuracy, demonstrating its adaptability and robustness across multiple instances.