In the present Internet Draft (ID) of PIM-SM, the IPsec Authentication Header (AH) protocol without anti-replay mechanism has been proposed to protect the link-local messages. This compromise makes PIM-SM vulnerable to Denial of Service (DoS) attack. Moreover, in this ID, the Security Association lookup and the required number of Security Associations are erroneous. In this paper, a new proposal is presented to protect PIM link-local messages while activating the anti-replay mechanism. The Security Association lookup method has also been modified. Finally, this proposal has been formally validated using SPIN.