Observability-Driven, Sniffer-Free Intrusion Detection for RPL: Closing the Detection Ceiling With On-Mote Control-Plane Features
Abstract
Intrusion detection in resource-constrained IoT networks typically relies on dedicated sniffer nodes, an architecture that does not transfer to heterogeneous deployments where adding monitoring hardware is operationally impractical. This paper presents a sniffer-free detection pipeline that operates exclusively on the integer counters each mote already maintains for normal operation of RPL (IPv6 Routing Protocol for Low-Power and Lossy Networks). Behavioral features are derived from these counters through configurable layers spanning statistical transforms, time-series characteristics, and dynamical complexity measures. The central mechanism is an observability-driven loop in which feature attribution is used not only to explain the trained model but to diagnose which behavioral signals the counter set fails to expose. The identified gaps motivate a firmware extension that exposes them. The pipeline is evaluated across $1{\,}200$ simulation runs spanning eight topology scales (25 to 400 nodes) under cross-topology evaluation, and on two public datasets. A diagnostic stage with standard counters reveals detection ceilings traced to specific control-plane signals absent from the default firmware. Retraining with the extended counter set raises every attack above 89% F1, with a unified detector reaching 94.2%, which confirms that the ceiling was an observability limit rather than a limit of classifier capacity. The machine-learning components are established tools, and the contribution is their coupling into this diagnostic loop together with the on-mote architecture that makes it deployable. The results indicate that detection in constrained IoT networks is bounded by what the mote reports, not by classifier sophistication.