A Network-based Event Detection Module Using NTP for Cyber Attacks on IoT

被引:1
作者
Kawamura, Tamotsu [1 ]
Fukushi, Masaru [2 ]
Hirano, Yasushi [2 ]
Fujita, Yusuke [2 ]
Hamamoto, Yoshihiko [2 ]
机构
[1] Il Ponte Corp, Kawasaki, Kanagawa, Japan
[2] Yamaguchi Univ, Grad Sch Sci & Technol Innovat, Ube, Yamaguchi, Japan
来源
2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS (CANDARW 2018) | 2018年
关键词
IoT; cyber attacks; event detection; NTP; INTRUSION DETECTION;
D O I
10.1109/CANDARW.2018.00025
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Developing countermeasures against cyber attacks is an urgent issue in Internet of Things (IoT) environment, and event detection is becoming increasingly important to detect events as the presages of a security incident. This paper proposes an event detection module which can be embedded into IoT devices. The proposed module focuses on the system behavior under cyber attacks and detects events utilizing information from Network Time Protocol (NTP) commonly used in network time synchronization service. This module works under a wireless access point (AP) and detects events on IoT devices linked to the AP. Different from the existing modules, it does not require any additional appliances nor periodic maintenance involving technical knowledges. We conducted demonstration experiments with the developed module generating pseudo cyber attacks. The result shows that the proposed module achieves high recall and precision values, indicating its usefulness in the real time event detection on IoT.
引用
收藏
页码:86 / 91
页数:6
相关论文
共 15 条
  • [1] [Anonymous], 2010, 6244321 IEC
  • [2] [Anonymous], 2013, 1SC27 ISOIEC JTC
  • [3] [Anonymous], MOB INF SYST
  • [4] Antonakakis M, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P1093
  • [5] Buragohain C., 2015, International Journal of Computer Applications, V123, P35
  • [6] An intelligent intrusion detection system (IDS) for anomaly and misuse detection in computer networks
    Depren, O
    Topallar, M
    Anarim, E
    Ciliz, MK
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2005, 29 (04) : 713 - 722
  • [7] The diagnostic odds ratio: a single indicator of test performance
    Glas, AS
    Lijmer, JG
    Prins, MH
    Bonsel, GJ
    Bossuyt, PMM
    [J]. JOURNAL OF CLINICAL EPIDEMIOLOGY, 2003, 56 (11) : 1129 - 1135
  • [8] Internet Initiative Japan Inc, 2016, INTERNET INFRASTRUCT, V33, P4
  • [9] Jagemar M., 2016, THESIS
  • [10] Kim H., 2016, P 4 IEEE INT C FUT I, P22