Multi-Trace: Solving the Data Scarcity Problem in IoT Intrusion Detection

Multi-Trace: Multi-level Data Trace Generation with the Cooja Simulator

2021-07-01
Niclas Finne, Joakim Eriksson, Thiemo Voigt, George Suciu, Mari-Anais Sachian, JeongGil Ko, Hossein Keipour
Summary
Problem
Method
Results
Takeaways
Abstract

Multi-Trace is a multi-level data trace generation framework that extends the Cooja simulator for wireless multi-hop networks. It enables the creation of diverse, large-scale datasets for training machine learning-based Intrusion Detection Systems (IDS) by capturing logs at the application, radio, and event levels with a unified global timestamp.

TL;DR

To build effective AI-driven security for the Internet of Things, we need data—lots of it. However, multi-hop wireless networks are notoriously difficult to monitor. Multi-Trace is a powerful extension of the Cooja simulator that allows researchers to generate massive, high-fidelity datasets by logging activity at multiple layers—from radio interference to application messages—all synchronized by a single global clock.

The Problem: The "Visibility Gap" in Multi-Hop Networks

In a standard WiFi network, a single packet sniffer can usually capture all local traffic. In a wireless multi-hop network (like those used in smart cities or industrial sensing), nodes are spread out. No single gateway can "hear" everything.

Current research in Intrusion Detection Systems (IDS) often suffers from:

  • Small Datasets: Models trained on just one or two topologies fail in the real world.
  • Lack of Ground Truth: It is hard to know exactly when an attack started or which node was truly affected by interference.
  • Manual Effort: Existing tools often require manual setup for every simulation run.

Methodology: High-Fidelity, Automated Tracing

The authors introduce Multi-Trace, which moves beyond simple log capturing by modifying the Cooja Simulator itself.

1. Multi-Level Logging

Multi-Trace captures four distinct types of data simultaneously:

  • Application Logs: Custom messages from the node's firmware.
  • Radio Logger (pcap): Standard packet-level data.
  • Radio Medium Logs: Detailed information about which nodes received a packet and which ones suffered from interference (crucial for detecting jamming).
  • Event Logs: Metadata marking when the network stabilized or when an attack was initiated.

Multi-Trace Architecture Fig 1: Multi-Trace extends Cooja to generate synchronized logs across multiple architectural layers.

2. The Attack Mechanism: Blackhole Attacks

To test the system, the authors implemented a Blackhole attack. They used a "hook" in the network stack to intercept RPL (Routing Protocol for Low-Power and Lossy Networks) messages. The malicious node broadcasts fake routing info (low rank) to trick neighbors into routing traffic through it, only to silently drop the packets.

3. Automation Pipeline

A Python-based suite allows for:

  • Random Topology Generation: Automatically shuffling node positions.
  • Steady-State Detection: Ensuring attacks only start once the network is fully formed.
  • CLI Triggering: Sending commands via a virtual serial port to turn attacks on/off.

Performance and Results

A key requirement for Machine Learning is volume. The authors evaluated Multi-Trace's efficiency on a 2016 MacBook Pro.

  • Scalability: While simulation time increases with node count, the system remains highly efficient.
  • Throughput: For a 20-node network, Multi-Trace generates over 160 traces per hour. This allows a researcher to build a dataset of thousands of scenarios (different topologies, attack nodes, and traffic patterns) in less than a day.

Simulation Performance Fig 2: Traces generated per hour vs. Number of nodes. The efficiency makes large-scale DL training feasible.

Critical Analysis & Conclusion

Takeaway: Multi-Trace addresses a critical bottleneck in IoT security research. By providing a standardized way to generate multi-level ground-truth data, it enables the application of modern Deep Learning (like LSTMs or Transformers) to time-series network data.

Limitations:

  • Single-Core Limitation: Cooja currently runs on a single CPU core. While the authors suggest running multiple simulations in parallel, native multi-threading in the simulator would be a significant upgrade.
  • Realism: While Cooja is excellent, simulator-to-hardware "gap" remains a challenge in all virtual environments.

Future Outlook: This tool is a "gold mine" for researchers looking into Edge AI. By understanding what data is available at the node level versus the gateway level, developers can decide where to host their IDS logic to minimize energy consumption while maximizing security.

Find Similar Papers

Try Our Examples

  • Find recent papers that utilize the Multi-Trace framework or similar Cooja extensions to train deep learning models for RPL-based intrusion detection.
  • What are the primary theoretical differences between the Blackhole attack and the Grayhole attack in IPv6-based low-power and lossy networks (LLNs)?
  • Explore how federated learning or distributed ML approaches have been applied to multi-hop wireless sensor networks to mitigate the energy cost of centralized logging.
Contents
Multi-Trace: Solving the Data Scarcity Problem in IoT Intrusion Detection
1. TL;DR
2. The Problem: The "Visibility Gap" in Multi-Hop Networks
3. Methodology: High-Fidelity, Automated Tracing
3.1. 1. Multi-Level Logging
3.2. 2. The Attack Mechanism: Blackhole Attacks
3.3. 3. Automation Pipeline
4. Performance and Results
5. Critical Analysis & Conclusion