Hybrid approach to intrusion detection in fog-based IoT environments

被引:85
|
作者
de Souza, Cristiano Antonio [1 ]
Westphall, Carlos Becker [2 ]
Machado, Renato Bobsin [3 ]
Mangueira Sobral, Joao Bosco [2 ]
Vieira, Gustavo dos Santos [4 ]
机构
[1] Univ Fed Santa Catarina, Comp Sci, Florianopolis, SC, Brazil
[2] Univ Fed Santa Catarina, Florianopolis, SC, Brazil
[3] State Univ Western Parana, Grad Program Elect & Comp Engin PGEEC, Foz Do Iguacu, Parana, Brazil
[4] State Univ Western Parana, Foz Do Iguacu, Parana, Brazil
关键词
Internet of things; Intrusion detection; Fog computing; Machine learning; DEEP LEARNING APPROACH; NEURAL-NETWORK; INTERNET; OPTIMIZATION; HYPERGRAPH; FRAMEWORK; IDS;
D O I
10.1016/j.comnet.2020.107417
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In the Internet of Things (IoT) systems, information of various kinds is continuously captured, processed, and transmitted by systems generally interconnected by the Internet and distributed solutions. Attacks to capture information and overload services are common. This fact makes security techniques indispensable in IoT en-vironments. Intrusion detection is one of the vital security points, aimed at identifying attempted attacks. The characteristics of IoT devices make it impossible to apply these solutions in this environment. Also, the existing anomaly-based methods for multiclass detection do not present acceptable accuracy. We present an intrusion detection architecture that operates in the fog computing layer. It has two steps and aims to classify events into specific types of attacks or non-attacks, for the execution of countermeasures. Our work presents a relevant con-tribution to the state of the art in this aspect. We propose a hybrid binary classification method called DNN-kNN. It has high accuracy and recall rates and is ideal for composing the first level of the two-stage detection method of the presented architecture. The approach is based on Deep Neural Networks (DNN) and the k-Nearest Neighbor (kNN) algorithm. It was evaluated with the public databases NSL-KDD and CICIDS2017. We used the method of selecting attributes based on the rate of information gain. The approach proposed in this work obtained 99.77% accuracy for the NSL-KDD dataset and 99.85% accuracy for the CICIDS2017 dataset. The experimental results showed that the proposed hybrid approach was able to achieve greater precision about classic machine learning approaches and the recent advances in intrusion detection for IoT systems. In addition, the approach works with low overhead in terms of memory and processing costs.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] A Distributed Fog-based Access Control Architecture for IoT
    Alnefaie, Seham
    Cherif, Asma
    Alshehri, Suhair
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (12): : 4545 - 4566
  • [22] Fog-based Secure Communications for Low-power IoT Devices
    Ferretti, Luca
    Marchetti, Mirco
    Colajanni, Michele
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2019, 19 (02)
  • [23] Fog-based semantic model for supporting interoperability in IoT
    Rahman, Hafizur
    Hussain, Md. Iftekhar
    IET COMMUNICATIONS, 2019, 13 (11) : 1651 - 1661
  • [24] A Novel Intrusion Detection Approach Using Machine Learning Ensemble for IoT Environments
    Verma, Parag
    Dumka, Ankur
    Singh, Rajesh
    Ashok, Alaknanda
    Gehlot, Anita
    Malik, Praveen Kumar
    Gaba, Gurjot Singh
    Hedabou, Mustapha
    APPLIED SCIENCES-BASEL, 2021, 11 (21):
  • [25] Performance Modeling and Optimization for a Fog-Based IoT Platform
    Tang, Shensheng
    IOT, 2023, 4 (02): : 183 - 201
  • [26] Network Intrusion Detection for IoT Security Based on Learning Techniques
    Chaabouni, Nadia
    Mosbah, Mohamed
    Zemmari, Akka
    Sauvignac, Cyrille
    Faruki, Parvez
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2019, 21 (03): : 2671 - 2701
  • [27] Energy-Efficient and delay-guaranteed computation offloading for fog-based IoT networks
    Shahryari, Om-Kolsoom
    Pedram, Hossein
    Khajehvand, Vahid
    TakhtFooladi, Mehdi Dehghan
    COMPUTER NETWORKS, 2020, 182
  • [28] Energy saving scheduling in a fog-based IoT application by Bayesian task classification approach
    Heydari G.
    Rahbari D.
    Nickray M.
    Turkish Journal of Electrical Engineering and Computer Sciences, 2019, 27 (06): : 4167 - 4187
  • [29] A Network Intrusion Detection Approach at the Edge of Fog
    Azarkasb, Seyed Omid
    Kashi, Saeed Sedighian
    Khasteh, Seyed Hossein
    2021 26TH INTERNATIONAL COMPUTER CONFERENCE, COMPUTER SOCIETY OF IRAN (CSICC), 2021,
  • [30] A Comprehensive Approach to Intrusion Detection in IoT Environments Using Hybrid Feature Selection and Multi-Stage Classification Techniques
    Logeswari, G.
    Roselind, J. Deepika
    Tamilarasi, K.
    Nivethitha, V.
    IEEE ACCESS, 2025, 13 : 24970 - 24987