Even when 6LoWPAN has an ideal cryptography line defense, it is still necessary to implement an intrusion detection system (IDS) to deal with threats targeting network performance such as DoS attacks. IDS discover and stop most attacks that make changes on the operation of the network. However, few IDS solution has been proposed for 6LoWPAN networks. IDS missions are to monitor and raise an alarm about any possible threats and pass it to the system to restart the keying process for eliminating the attackers. New technique has been proposed recently based on the principle that neighbor nodes have a trend to have the same behavior, so the detection of the malicious node is based on the detection of the abnormal node that has a bad behavior different than it neighbors. The security goal is to provide a monitoring system that will attempt to detect anomalous malicious behavior and to prevent it from harming the network performance basing on the neighbors nodes behavior monitoring.