Please wait ...
0% Complete
Home
/
15th International Conference on Computer and Knowledge Engineering
DTranIDS: A Two-Tiered Intrusion Detection System for RPL-based IoT Networks based on Decision Tree and Transformer Models
Authors :
Mohammad Fazeli
1
Mohsen Raji
2
Mohammad Mahdi Fazeli
3
1- School of Electrical and Computer Engineering, University of Shiraz, Iran
2- School of Electrical and Computer Engineering, University of Shiraz, Iran
3- School of Electrical and Computer Engineering, University of Shiraz, Iran
Keywords :
IoT Security،RPL attacks،Anomaly Detection،Anomaly Detection،Decision Tree،Transformer،Two-Tiered Model،Intrusion Detection System
Abstract :
RPL (Routing Protocol for Low-Power and Lossy Networks) has emerged as the de facto standard for IoT routing, offering robust, energy-efficient, and scalable communication. However, its susceptibility to it unique cyber-security attacks demands robust security enhancements to ensure reliable deployment. Although Intrusion Detection Systems (IDS) offer a proactive defense mechanism to mitigate RPL's inherent vulnerabilities, traditional IDS solutions are often too resource-intensive for IoT environments. Therefore, there is a critical need for lightweight-yet-accurate IDS frameworks specifically designed for RPL-based networks. In this paper, we propose a novel two-tier intrusion detection system, DTranIDS, designed to effectively identify and classify RPL-specific attacks in IoT environments. In the first tier, a Decision Tree classifier rapidly filters incoming data to determine whether a given instance is benign or malicious. In the second tier, a Transformer-based model is employed to precisely classify the specific type of detected attack. The proposed model is evaluated using the ROUT-4-2023 dataset, which includes four common RPL routing attacks: Blackhole, Flooding, Version Number, and Decreased Rank. Experimental results demonstrate that DTranIDS achieves an overall accuracy of 97%, with precision, recall, and F1-score values all around 96%, significantly outperforming several state-of-the-art IoT intrusion detection methods (which typically achieve 88–91% accuracy). Moreover, DTranIDS show its efficiency in fast intrusion detection (about 0.4 s), indicating that DTranIDS is well-suited for real-world, resource-constrained IoT environments, offering both real-time intrusion detection and detailed attack classification capabilities to aid cybersecurity analysts.
Papers List
List of archived papers
SASIAF, An Scalable Accelerator For Seismic Imaging on Amazon AWS FPGAs
Mostafa Koraei - S.Omid Fatemi
Low-Cost and Hardware Efficient Implementation of Pooling Layers for Stochastic CNN Accelerators
Mobin Vaziri - Hadi Jahanirad
A supervised approach using transformer networks for the detection of turning-related anomalies in urban intersections
Mohammad Mahdi HajiAbadi - Manoochehr Nahvi
The application of Brain Drain Optimization algorithm on static drone placement problem
Mohammad Mehdi Samimi - Alireza Basiri
Dynamic Hand Gesture Recognition with 2DCNN-LSTM and Improved Keyframe Extraction
Narjes Heidari - Javid Norouzi - Mohammad Sadegh Helfroush - Habibollah Danyal
A 2D-CNN Architecture for Improving the Classification Accuracy of an Electronic Nose with Different Sensor Positions
Hannaneh Mahdavi - Reza Goldoust - Saeideh Rahbarpour
Disturbance Rejection in Quadruple-Tank System by Proposing New Method in Reinforcement Learning
Alireza Nezamzadeh - Mohammadreza Esmaeilidehkordi
Lightweight Local Transformer for COVID-19 Detection Using Chest CT Scans
Hojat Asgarian Dehkordi - Hossein Kashiani - Amir Abbas Hamidi Imani - Shahriar Baradaran Shokouhi
Graph Representation Learning Towards Patents Network Analysis
Mohammad Heydari - Babak Teimourpour
Financial Market Prediction Using Deep Neural Networks with Hardware Acceleration
Dara Rahmati - Mohammad Hadi Foroughi - Ali Bagherzadeh - Mehdi Foroughi - Saeid Gorgin
more
Samin Hamayesh - Version 44.9.3