Conditional entropy-based hybrid DDoS detection model for IoT networks

被引:0
|
作者
Pandey, Nimisha [1 ]
Mishra, Pramod Kumar [1 ]
机构
[1] Banaras Hindu Univ, Inst Sci, Dept Comp Sci, Varanasi, India
关键词
Entropy; DDoS attack; Attack detection; IoT; ATTACKS;
D O I
10.1016/j.cose.2024.104199
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ina distributed denial-of-service (DDoS) attack, an attacker channelizes the resources of a botnet to launch denial of service attack on the victim. The increased use of IoT devices and dependence of users on e-services like online shopping and online payments have elevated the liability risks. The entropy provides a significant measure of randomness. The variation in entropy of traffic features determines the presence of abrupt traffic. This paper uses entropy and conditional entropy to achieve insights on data and feeds it to the proposed 2-stage detection approach for multi-class classification. The proposed model employs four classifiers for first hand classification. Further, stacking generalization-based second stage achieves the final detection process. The recently launched CIC IoT 2023 dataset is used to illustrate the findings of the study. The proposed approach produces an accuracy of 99.86%. Further, this paper utilizes relative entropy for the determination of deflection of traffic behavior between the attack and legitimate samples. Comparisons have been made among symmetric versions of information divergence, cent-divergence and Kullback-Leibler divergence along with, Hellinger distance and total variation distance. It is found that the information distance gives abetter differentiation between the entropy of legitimate traffic and attack traffic. Significance Statement Entropy has been manipulated to define the nature of incoming traffic for any rule-based detection. This work explores the significance of conditional entropy for the ML-based detection of DDoS attacks in a recently launched IoT-based dataset. Additionally, the effectiveness of KL-divergence, information divergence, cent-divergence, Hellinger distance and total variation distance is compared for differentiating between legitimate traffic and attack traffic.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] Entropy-based Inhomogeneity Detection in Fiber Materials
    Patricia Alonso Ruiz
    Evgeny Spodarev
    Methodology and Computing in Applied Probability, 2018, 20 : 1223 - 1239
  • [42] Trust evaluation model with entropy-based weight assignment for malicious node’s detection in wireless sensor networks
    Xueqiang Yin
    Shining Li
    EURASIP Journal on Wireless Communications and Networking, 2019
  • [43] An Entropy-Based Network Anomaly Detection Method
    Berezinski, Przemyslaw
    Jasiul, Bartosz
    Szpyrka, Marcin
    ENTROPY, 2015, 17 (04) : 2367 - 2408
  • [44] Entropy-Based Economic Denial of Sustainability Detection
    Sotelo Monge, Marco Antonio
    Maestre Vidal, Jorge
    Garcia Villalba, Luis Javier
    ENTROPY, 2017, 19 (12)
  • [45] Evaluation of entropy-based detection of outbound denial-of-service attacks in edge networks
    Basicevic, Ilija
    Ocovaj, Stanislav
    Popovic, Miroslav
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (05) : 837 - 844
  • [46] Rule Acquisition with an Entropy-based Hybrid Genetic Algorithm
    Wan, Liyong
    Zhao, Chengling
    2009 INTERNATIONAL CONFERENCE ON NETWORKING AND DIGITAL SOCIETY, VOL 2, PROCEEDINGS, 2009, : 275 - +
  • [47] Entropy-Based Anomaly Detection Using Observation Points Relations in Wireless Sensor Networks
    Ahmad Shahab Arkan
    Mahmood Ahmadi
    Wireless Personal Communications, 2021, 119 : 1783 - 1798
  • [48] Optimized Edge-cCCN Based Model for the Detection of DDoS Attack in IoT Environment
    Gupta, Brij B.
    Gaurav, Akshat
    Chui, Kwok Tai
    Arya, Varsha
    EDGE COMPUTING - EDGE 2023, 2024, 14205 : 14 - 23
  • [49] Detection of DDoS Attacks on Urban IoT Devices Using Neural Networks
    Obetta, Simon Onyebuchi
    Moldovan, Arghir-Nicolae
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY, IOTBDS 2023, 2023, : 236 - 242
  • [50] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71