Data driven intrusion detection for 6LoWPAN based IoT systems

被引:2
|
作者
Ors, Faik Kerem [1 ,2 ]
Levi, Albert [1 ]
机构
[1] Sabanci Univ, Fac Engn & Nat Sci, Istanbul, Turkiye
[2] Purdue Univ, Dept Comp Sci, W Lafayette, IN USA
关键词
Internet of Things; Intrusion detection; Attack classification; Anomaly detection; Machine learning; ROUTING ATTACKS; INTERNET; NETWORKS;
D O I
10.1016/j.adhoc.2023.103120
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Wide adoption of Internet of Things (IoT) devices and their limitations in terms of hardware cause them to be easy targets for attackers. This, in turn, requires monitoring such systems using intrusion detection systems and take mitigative actions against insider and outsider attackers. Recent studies have explored that machine learning based intrusion detection systems are quite successful in detecting different types of cyber threats targeting IoT systems. However, the proposed systems in these studies incurred limitations in terms of the characteristics of their datasets and detection models. Specifically, a big proportion of the proposed models were developed using simulation-based data generated through specific simulators. Some of these studies also used previously published testbed data that contain the samples of outdated IoT attacks and vulnerabilities. Furthermore, they focused on a lower attack variety and proposed binary classifiers which do not scale in multi-attack scenarios. In this study, we propose a machine learning based multi-class classifier that can classify 6 attack types together with the benign traffic. Our node based feature extraction and detection methodology allows locating the network addresses of the attackers, rather than a rough network level attack existence information, by modeling their traffic characteristics over a sliding time window. For training and testing our models, we also propose an intrusion detection dataset generated using the traffic data collected from real IoT devices running with 6LoWPAN and RPL protocols. Besides having RPL routing attacks in the dataset, we leverage Mirai botnet, employed frequently to target IoT devices. The results show that the proposed intrusion detection system can detect 6 attack types with high recall scores ranging from 79% to 100%. We also illustrate the practicality of the developed model via deployment in a proof of concept implementation over a testbed.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Data Mining and Intrusion Detection Systems
    Dewa, Zibusiso
    Maglaras, Leandros A.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (01) : 62 - 71
  • [42] Design and Implementation of Lightweight 6LoWPAN Gateway Based on Contiki
    Zhao Honggang
    Shi Chen
    Zhai Leyu
    2018 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATIONS AND COMPUTING (ICSPCC), 2018,
  • [43] The impact of copycat attack on RPL based 6LoWPAN networks in Internet of Things
    Verma, Abhishek
    Ranga, Virender
    COMPUTING, 2021, 103 (07) : 1479 - 1500
  • [44] A hybrid IDS for detection and mitigation of sinkhole attack in 6LoWPAN networks
    Pradeepkumar Bhale
    Santosh Biswas
    Sukumar Nandi
    International Journal of Information Security, 2024, 23 : 915 - 934
  • [45] Analysis of Routing Attacks on RPL based 6LoWPAN Networks
    Verma, Abhishek
    Ranga, Virender
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2018, 11 (08): : 43 - 56
  • [46] Data-Driven Trust Prediction in Mobile Edge Computing-Based IoT Systems
    Abeysekara, Prabath
    Dong, Hai
    Qin, A. K.
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (01) : 246 - 260
  • [47] DSAT-IDS: Dissimilarity and Adaptive Threshold-based Intrusion Detection system to mitigate selective forwarding attack in the RPL-based 6LoWPAN
    Rajasekar, V. R.
    Rajkumar, S.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (09): : 12029 - 12068
  • [48] An SDN-based Hybrid-DL-driven cognitive intrusion detection system for IoT ecosystem
    Wahab, Fazal
    Shah, Anwar
    Khan, Imran
    Ali, Bahar
    Adnan, Muhammad
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 119
  • [50] A Review on Intrusion Detection System for IoT based Systems
    Samita
    SN Computer Science, 5 (4)