Conditional entropy-based hybrid DDoS detection model for IoT networks

被引:0
|
作者
Pandey, Nimisha [1 ]
Mishra, Pramod Kumar [1 ]
机构
[1] Banaras Hindu Univ, Inst Sci, Dept Comp Sci, Varanasi, India
关键词
Entropy; DDoS attack; Attack detection; IoT; ATTACKS;
D O I
10.1016/j.cose.2024.104199
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ina distributed denial-of-service (DDoS) attack, an attacker channelizes the resources of a botnet to launch denial of service attack on the victim. The increased use of IoT devices and dependence of users on e-services like online shopping and online payments have elevated the liability risks. The entropy provides a significant measure of randomness. The variation in entropy of traffic features determines the presence of abrupt traffic. This paper uses entropy and conditional entropy to achieve insights on data and feeds it to the proposed 2-stage detection approach for multi-class classification. The proposed model employs four classifiers for first hand classification. Further, stacking generalization-based second stage achieves the final detection process. The recently launched CIC IoT 2023 dataset is used to illustrate the findings of the study. The proposed approach produces an accuracy of 99.86%. Further, this paper utilizes relative entropy for the determination of deflection of traffic behavior between the attack and legitimate samples. Comparisons have been made among symmetric versions of information divergence, cent-divergence and Kullback-Leibler divergence along with, Hellinger distance and total variation distance. It is found that the information distance gives abetter differentiation between the entropy of legitimate traffic and attack traffic. Significance Statement Entropy has been manipulated to define the nature of incoming traffic for any rule-based detection. This work explores the significance of conditional entropy for the ML-based detection of DDoS attacks in a recently launched IoT-based dataset. Additionally, the effectiveness of KL-divergence, information divergence, cent-divergence, Hellinger distance and total variation distance is compared for differentiating between legitimate traffic and attack traffic.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Performance analysis of entropy variation-based detection of DDoS attacks in IoT
    Pandey, Nimisha
    Mishra, Pramod Kumar
    INTERNET OF THINGS, 2023, 23
  • [2] Entropy and Divergence-based DDoS Attack Detection System in IoT Networks
    Saiyed, Makhduma
    Al Anbagi, Irfan
    2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB, 2023, : 224 - 230
  • [3] Entropy-Based Application Layer DDoS Attack Detection Using Artificial Neural Networks
    Singh, Khundrakpam Johnson
    Thongam, Khelchandra
    De, Tanmay
    ENTROPY, 2016, 18 (10)
  • [4] Entropy-based DDoS Attack Detection in Cluster-based Mobile Ad Hoc Networks
    Deepa
    Dhindsa, Kanwalvir Singh
    Singh, Karanbir
    AD HOC & SENSOR WIRELESS NETWORKS, 2021, 49 (3-4) : 269 - 288
  • [5] DDoS attack detection in SDN: Enhancing entropy-based detection with machine learning
    Santos-Neto, Marcos J.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    Ishikawa, Edison
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (11)
  • [6] A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic
    Tian, Qiwen
    Miyata, Sumiko
    IOT, 2023, 4 (02): : 95 - 111
  • [7] Adaptive DDoS Attack Detection: Entropy-Based Model With Dynamic Threshold and Suspicious IP Reevaluation
    Pebrianto, Juri
    Suryani, Vera
    IEEE ACCESS, 2025, 13 : 55858 - 55876
  • [8] Robust detection of unknown DoS/DDoS attacks in IoT networks using a hybrid learning model
    Nguyen, Xuan-Ha
    Le, Kim-Hung
    INTERNET OF THINGS, 2023, 23
  • [9] Early detection of DDoS based on φ-entropy in SDN networks
    Li, Runyu
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 731 - 735
  • [10] An Entropy Based Approach for DDoS Attack Detection in IEEE 802.16 Based Networks
    Shojaei, Maryam
    Movahhedinia, Naser
    Ladani, Behrouz Tork
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, 2011, 7038 : 129 - 143