Skip to main navigation Skip to search Skip to main content

A Data Collection System from the RPL Routing Protocol for Detecting Distributed Denial of Service Attacks in IoT Networks

  • Anastasiia Nicheporuk
  • , Andrii Nicheporuk
  • , Andrzej Kwiecien
  • , Serhii Posonskyi
  • , Galina Radelchuk
  • Khmelnytsky National University

Research output: Contribution to journalConference articlepeer-review

Abstract

The work presents a data collection system from the RPL routing protocol for detecting distributed denial-of-service attacks in Internet of Things (IoT) networks operating on the basis of the 6LoWPAN and RPL protocols. The system consists of three modules: a data gathering module, a classification module and a detection module. The main feature of the data collection module was that data collection was provided by several sniffers installed in the network and with subsequent aggregation of the collected data. For the implementation of the classification module, research was carried out on the method of support vector machines (SVM) and a multilayer perceptron (MLP). The detection module was used to broadcast a message about the abnormal behavior to the rest of the IoT network nodes, containing the ID of the compromised node and the path to it. To evaluate the efficiency of the proposed system that is based on the data collected by the data gathering module, a number of experiments were conducted. To obtain the data set for the experiments, an infrastructure based on the Ubuntu operating system and the Cooja simulator was deployed, which allowed to simulate the RPL network. Based on the operation of the deployed network, network traffic was collected that corresponded to both legitimate traffic and traffic during a black hole attack. The total number of test data was 24,023 samples. According to the research results, it was established that the SVM-based model demonstrated better performance level, in particular, the accuracy of detecting denial-of-service attacks was 89.6%, while the rate of false positives was 6%.

Original languageEnglish
Pages (from-to)411-424
Number of pages14
JournalCEUR Workshop Proceedings
Volume3373
Publication statusPublished - 2023
Event4th International Workshop on Intelligent Information Technologies and Systems of Information Security, IntellTSIS 2023 - Khmelnytskyi, Ukraine
Duration: 22 Mar 202324 Mar 2023

Keywords

  • Contiki
  • RPL protocol
  • anomaly detection
  • black hole attack
  • denial of service attack
  • sniffer

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'A Data Collection System from the RPL Routing Protocol for Detecting Distributed Denial of Service Attacks in IoT Networks'. Together they form a unique fingerprint.

Cite this