A comprehensive deep learning benchmark for IoT IDS

被引:34
作者
Ahmad, Rasheed [1 ]
Alsmadi, Izzat [2 ]
Alhamdani, Wasim [1 ]
Tawalbeh, Lo'ai [2 ]
机构
[1] Univ Cumberlands, 6178 Coll Stn Dr, Williamsburg, KY 40769 USA
[2] Univ Texas A&M San Antonio, One Univ Way, San Antonio, TX 78224 USA
关键词
Intrusion detection system (IDS); Machine learning; Deep learning; Large-scale attacks; Internet of Things (IoT); Benchmark network dataset; NETWORK INTRUSION DETECTION; ATTACK DETECTION; DETECTION SYSTEM; INTERNET; THINGS; SURVEILLANCE; ANALYTICS; FRAMEWORK;
D O I
10.1016/j.cose.2021.102588
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The significance of an intrusion detection system (IDS) in networks security cannot be overstated in detecting and responding to malicious attacks. Failure to detect large-scale attacks like DDoS not only makes the networks vulnerable, but a failure of critical lifesaving medical and industrial equipment can also put human lives at risk. Lack of availability of comprehensive and quality network datasets and the narrow scope to build an IDS based on a single machine learning classifier adds further limitations. Such issues can risk producing inaccurate or biased results in the solutions proposed by various researchers. Toward this end, this paper analyzed several datasets (old, recent, non-IoT, and IoT specific) using several individual and hybrid deep learning classifiers. Our goal is to establish a benchmark that can compare several classification models on several datasets to limit (1) dataset quality issues and (2) possible bias in produced results. We reported our empirical results by revealing exciting findings on some of the classifiers, which took hours to converge but could not successfully detect attacks. In contrast, others quickly converged and were able to produce the best results in terms of accuracy and other performance metrics. We believe that this paper's findings will help build a comprehensive IDS by recognizing that classification or prediction models should be trained beyond a limited scope of one dataset or application. (C) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:22
相关论文
共 100 条
  • [1] Machine learning approaches to IoT security: A systematic literature review
    Ahmad, Rasheed
    Alsmadi, Izzat
    [J]. INTERNET OF THINGS, 2021, 14
  • [2] Network intrusion detection system: A systematic study of machine learning and deep learning approaches
    Ahmad, Zeeshan
    Shahid Khan, Adnan
    Wai Shiang, Cheah
    Abdullah, Johari
    Ahmad, Farhan
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (01)
  • [3] Akbari A., 2021, P MACHINE LEARNING R, P141
  • [4] Real-Time Secure Health Surveillance for Smarter Health Communities
    Alabdulatif, Abdulatif
    Khalil, Ibrahim
    Forkan, Abdur Rahim Mohammad
    Atiquzzaman, Mohammed
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2019, 57 (01) : 122 - 129
  • [5] Alsamiri J, 2019, INT J ADV COMPUT SC, V10, P627
  • [6] [Anonymous], 2020, Sygehusmedicinregistret datadeklaration.pdf Internet
  • [7] A Supervised Intrusion Detection System for Smart Home IoT Devices
    Anthi, Eirini
    Williams, Lowri
    Slowinska, Malgorzata
    Theodorakopoulos, George
    Burnap, Pete
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05): : 9042 - 9053
  • [8] Assessing risks and threats with layered approach to Internet of Things security
    Aydos, Murat
    Vural, Yilmaz
    Tekerek, Adem
    [J]. MEASUREMENT & CONTROL, 2019, 52 (5-6) : 338 - 353
  • [9] Aygun R. Can, 2017, 2017 IEEE 4th International Conference on Cyber-Security and Cloud Computing (CSCloud), P193, DOI 10.1109/CSCloud.2017.39
  • [10] Bai S., 2018, ARXIV180301271