Data driven intrusion detection for 6LoWPAN based IoT systems

被引:2
|
作者
Ors, Faik Kerem [1 ,2 ]
Levi, Albert [1 ]
机构
[1] Sabanci Univ, Fac Engn & Nat Sci, Istanbul, Turkiye
[2] Purdue Univ, Dept Comp Sci, W Lafayette, IN USA
关键词
Internet of Things; Intrusion detection; Attack classification; Anomaly detection; Machine learning; ROUTING ATTACKS; INTERNET; NETWORKS;
D O I
10.1016/j.adhoc.2023.103120
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Wide adoption of Internet of Things (IoT) devices and their limitations in terms of hardware cause them to be easy targets for attackers. This, in turn, requires monitoring such systems using intrusion detection systems and take mitigative actions against insider and outsider attackers. Recent studies have explored that machine learning based intrusion detection systems are quite successful in detecting different types of cyber threats targeting IoT systems. However, the proposed systems in these studies incurred limitations in terms of the characteristics of their datasets and detection models. Specifically, a big proportion of the proposed models were developed using simulation-based data generated through specific simulators. Some of these studies also used previously published testbed data that contain the samples of outdated IoT attacks and vulnerabilities. Furthermore, they focused on a lower attack variety and proposed binary classifiers which do not scale in multi-attack scenarios. In this study, we propose a machine learning based multi-class classifier that can classify 6 attack types together with the benign traffic. Our node based feature extraction and detection methodology allows locating the network addresses of the attackers, rather than a rough network level attack existence information, by modeling their traffic characteristics over a sliding time window. For training and testing our models, we also propose an intrusion detection dataset generated using the traffic data collected from real IoT devices running with 6LoWPAN and RPL protocols. Besides having RPL routing attacks in the dataset, we leverage Mirai botnet, employed frequently to target IoT devices. The results show that the proposed intrusion detection system can detect 6 attack types with high recall scores ranging from 79% to 100%. We also illustrate the practicality of the developed model via deployment in a proof of concept implementation over a testbed.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Evaluation of Network Intrusion Detection Systems for RPL Based 6LoWPAN Networks in IoT
    Verma, Abhishek
    Ranga, Virender
    WIRELESS PERSONAL COMMUNICATIONS, 2019, 108 (03) : 1571 - 1594
  • [2] Evaluation of Network Intrusion Detection Systems for RPL Based 6LoWPAN Networks in IoT
    Abhishek Verma
    Virender Ranga
    Wireless Personal Communications, 2019, 108 : 1571 - 1594
  • [3] 6MID:Mircochain based Intrusion Detection for 6LoWPAN based IoT networks
    Patel, Himanshu B.
    Jinwala, Devesh C.
    12TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT) / THE 4TH INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40) / AFFILIATED WORKSHOPS, 2021, 184 : 929 - 934
  • [4] Intrusion Detection Systems in RPL-Based 6LoWPAN: A Systematic Literature Review
    Pasikhani, Aryan Mohammadi
    Clark, John A.
    Gope, Prosanta
    Alshahrani, Abdulmonem
    IEEE SENSORS JOURNAL, 2021, 21 (11) : 12940 - 12968
  • [5] Incremental hybrid intrusion detection for 6LoWPAN
    Pasikhan, Aryan Mohammadi
    Clark, John A.
    Gope, Prosanta
    COMPUTERS & SECURITY, 2023, 135
  • [6] Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
    Napiah, Mohamad Nazrin
    Bin Idris, Mohd Yamani Idna
    Ramli, Roziana
    Ahmedy, Ismail
    IEEE ACCESS, 2018, 6 : 16623 - 16638
  • [7] Baseline Intrusion Detection Framework for 6LoWPAN Devices
    Patel, Himanshu B.
    Jinwala, Devesh C.
    Patel, Dhiren R.
    ADJUNCT PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING NETWORKING AND SERVICES (MOBIQUITOUS 2016), 2016, : 72 - 76
  • [8] A Software-Defined Networking framework for IoT based on 6LoWPAN
    Lasso, Fabian Fernando Jurado
    Clarke, Ken
    Nirmalathas, Ampalavanapillai
    2018 WIRELESS TELECOMMUNICATIONS SYMPOSIUM (WTS), 2018,
  • [9] A Survey on 6LoWPAN Security for IoT: Taxonomy, Architecture, and Future Directions
    Thungon, Leki Chom
    Ahmed, Nurzaman
    De, Debashis
    Hussain, Md. Iftekhar
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 137 (01) : 153 - 197
  • [10] IoT-Based Intrusion Detection Systems: A Review
    Mohamed, Tamara Saad
    Aydin, Sezgin
    SMART SCIENCE, 2022, 10 (04) : 265 - 282