This thesis investigates security in RPL-based Internet of Things (IoT) networks by examining the relationship between routing behavior and intrusion detection in constrained, low-power, and lossy environments. In such networks, attacks can be expressed through seemingly legitimate protocol operations, making conventional intrusion detection assumptions less reliable. The study therefore explores whether a trust aware routing strategy, implemented as TACR-HOF, can generate behavioural traces that are more informative for intrusion detection than those produced by the conventional Minimum Rank with Hysteresis Objective Function (MRHOF).
To address this problem, a comparative simulation framework was developed using Contiki-NG and the Cooja simulator. The same family of six topologies was evaluated under MRHOF and TACR HOF, while four RPL-specific attacks were introduced: Version Number Attack, Decrease Rank Attack, DIS Flooding Attack, and Selective Forwarding Attack. Rather than relying on full packet capture, the study employed behaviour-based summaries collected from nodes and their neighbours, which were transformed into structured datasets for machine-learning-based intrusion detection. This approach enabled a comparative analysis of both routing behaviour and the quality of the IDS-ready data produced under each routing scheme.
The results show that TACR-HOF provides a stronger foundation for behaviour-based intrusion detection than MRHOF. It produces a richer malicious-behaviour footprint, improves classification performance across all evaluated models, and significantly reduces the most critical IDS error, namely the misclassification of malicious behaviour as normal. Attack-wise recall also improves across all four attack classes, particularly for control-plane attacks involving rank and version manipulation. At the routing level, however, the results remain nuanced: TACR-HOF improves several scenario-level metrics, including packet delivery and missed transmissions in many cases, but it does not outperform MRHOF uniformly in every topology or routing metric.
Overall, the thesis concludes that TACR-HOF should not be considered universally superior for all routing purposes, but it is clearly more effective as a security-oriented routing approach. Its main contribution lies in demonstrating that modifying the routing objective function can improve the quality of behavioural evidence available to an intrusion detection system, making attacks more visible, more distinguishable, and easier to detect in constrained IoT networks.
| Date | 17 Jun 2026 |
|---|
| Original language | American English |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Michel Kadoch (Supervisor) |
|---|
Ghorchian, S. (Author),
Kadoch (Supervisor),
17 Jun 2026Student thesis: Master's thesis › Master in Engineering: Electrical Engineering