Flow and unified information-based DDoS attack detection system for multi-topology IoT networks

被引:5
作者
Saiyed, Makhduma F. [1 ]
Al-Anbagi, Irfan [1 ]
机构
[1] Univ Regina, Fac Engn & Appl Sci, Regina, SK S4S 0A2, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Greedy bin packing distance; Conditional entropy; DDoS attack; Event-driven architecture; High-volume attack; Information entropy; IoT security; KL divergence; Low-volume attack; Statistical analysis; ENTROPY;
D O I
10.1016/j.iot.2023.100976
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) networks are vulnerable to Distributed Denial of Service (DDoS) attacks, which can degrade their Quality of Service (QoS). In general, DDoS attacks are classified into high-and low-volume attacks. Existing statistical-based methods for DDoS attack detection in IoT networks are effective only for high-volume or low-volume attacks, but not for both. The majority of research in this domain relies on single-dimensional analysis and static thresholds. In response to these limitations, this paper introduces a Flow and Unified Information-based DDoS (FLUID) attack detection system, a lightweight statistical approach, for DDoS attack detection in IoT networks. The FLUID system incorporates multi-dimensional analysis by integrating unified information and flow behavior to effectively identify both high-and low -volume DDoS attacks. FLUID utilizes entropy and distance metrics, such as Kullback-Leibler (KL) divergence and greedy bin-packing, as unified information measures to distinguish legitimate traffic from malicious activity. Additionally, it examines flow behavior to gain insights into network traffic patterns. Notably, the FLUID system maintains its lightweight nature through a streamlined set of network features and optimized computational efficiency. Evaluations on real-world IoT client/server and Event-Driven Architecture (EDA) testbeds with the ToN-IoT, CICIDS 2017, CICIDS 2019, and DoS/DDoS-MQTT-IoT datasets show that the FLUID system can achieve over 90% detection accuracy for both high-and low-volume DDoS attacks.
引用
收藏
页数:23
相关论文
共 52 条
[1]   Statistical Application Fingerprinting for DDoS Attack Mitigation [J].
Ahmed, Muhammad Ejaz ;
Ullah, Saeed ;
Kim, Hyoungshick .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (06) :1471-1484
[2]   DoS/DDoS-MQTT-IoT: A dataset for evaluating intrusions in IoT networks using the MQTT protocol [J].
Alatram, Alaa ;
Sikos, Leslie F. ;
Johnstone, Mike ;
Szewczyk, Patryk ;
Kang, James Jin .
COMPUTER NETWORKS, 2023, 231
[3]   Identification of Distributed Denial of Services Anomalies by Using Combination of Entropy and Sequential Probabilities Ratio Test Methods [J].
Ali, Basheer Husham ;
Sulaiman, Nasri ;
Al-Haddad, Syed Abdul Rahman ;
Atan, Rodziah ;
Hassan, Siti Lailatul Mohd ;
Alghrairi, Mokhalad .
SENSORS, 2021, 21 (19)
[4]   Securing IoT Based Maritime Transportation System Through Entropy-Based Dual-Stack Machine Learning Framework [J].
Ali, Farhan ;
Sarwar, Sohail ;
Shafi, Qaisar M. ;
Iqbal, Muddesar ;
Safyan, Muhammad ;
Qayyum, Zia Ul .
IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (02) :2482-2491
[5]  
Alsakran F., 2019, INT S SEC COMP COMM, P87, DOI [DOI 10.1007/978-981-15-4825-3_7, 10.1007/978-981-15-4825-3_7]
[6]  
[Anonymous], 2019, U.S
[7]  
Arvind S, 2023, 2023 INT C DISTR COM, P1, DOI [10.1109/ICDCECE57866.2023.10150823, DOI 10.1109/ICDCECE57866.2023.10150823]
[8]   Detection of DDoS attacks and flash events using novel information theory metrics [J].
Behal, Sunny ;
Kumar, Krishan .
COMPUTER NETWORKS, 2017, 116 :96-110
[9]   A multi-step outlier-based anomaly detection approach to network-wide traffic [J].
Bhuyan, Monowar H. ;
Bhattacharyya, D. K. ;
Kalita, J. K. .
INFORMATION SCIENCES, 2016, 348 :243-271
[10]   ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets [J].
Booij, Tim M. ;
Chiscop, Irina ;
Meeuwissen, Erik ;
Moustafa, Nour ;
den Hartog, Frank T. H. .
IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (01) :485-496