ELBA-IoT: An Ensemble Learning Model for Botnet Attack Detection in IoT Networks

被引:61
作者
Abu Al-Haija, Qasem [1 ]
Al-Dala'ien, Mu'awya [1 ]
机构
[1] Princess Sumaya Univ Technol PSUT, Dept Comp Sci Cybersecur, Amman 11941, Jordan
关键词
Internet of Things (IoT); intrusion detection system (IDS); machine learning; ensemble learning; botnet attacks; anomaly detection;
D O I
10.3390/jsan11010018
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the prompt expansion and development of intelligent systems and autonomous, energy-aware sensing devices, the Internet of Things (IoT) has remarkably grown and obstructed nearly all applications in our daily life. However, constraints in computation, storage, and communication capabilities of IoT devices has led to an increase in IoT-based botnet attacks. To mitigate this threat, there is a need for a lightweight and anomaly-based detection system that can build profiles for normal and malicious activities over IoT networks. In this paper, we propose an ensemble learning model for botnet attack detection in IoT networks called ELBA-IoT that profiles behavior features of IoT networks and uses ensemble learning to identify anomalous network traffic from compromised IoT devices. In addition, our IoT-based botnet detection approach characterizes the evaluation of three different machine learning techniques that belong to decision tree techniques (AdaBoosted, RUSBoosted, and bagged). To evaluate ELBA-IoT, we used the N-BaIoT-2021 dataset, which comprises records of both normal IoT network traffic and botnet attack traffic of infected IoT devices. The experimental results demonstrate that our proposed ELBA-IoT can detect the botnet attacks launched from the compromised IoT devices with high detection accuracy (99.6%) and low inference overhead (40 mu-seconds). We also contrast ELBA-IoT results with other state-of-the-art results and demonstrate that ELBA-IoT is superior.
引用
收藏
页数:15
相关论文
共 45 条
[1]  
Abu Al-haija Qasem, 2022, Soft Computing for Security Applications: Proceedings of ICSCS 2021. Advances in Intelligent Systems and Computing (1397), P27, DOI 10.1007/978-981-16-5301-8_3
[2]   Detecting Port Scan Attacks Using Logistic Regression [J].
Abu Al-Haija, Qasem ;
Saleh, Eyad ;
Alnabhan, Mohammad .
2021 4TH INTERNATIONAL SYMPOSIUM ON ADVANCED ELECTRICAL AND COMMUNICATION TECHNOLOGIES (ISAECT), 2021,
[3]   Machine-Learning-Based Darknet Traffic Detection System for IoT Applications [J].
Abu Al-Haija, Qasem ;
Krichen, Moez ;
Abu Elhaija, Wejdan .
ELECTRONICS, 2022, 11 (04)
[4]   Top-Down Machine Learning-Based Architecture for Cyberattacks Identification and Classification in IoT Communication Networks [J].
Abu Al-Haija, Qasem .
FRONTIERS IN BIG DATA, 2022, 4
[5]   Attack-Aware IoT Network Traffic Routing Leveraging Ensemble Learning [J].
Abu Al-Haija, Qasem ;
Al-Badawi, Ahmad .
SENSORS, 2022, 22 (01)
[6]   Boost-Defence for resilient IoT networks: A head-to-toe approach [J].
Abu Al-Haija, Qasem ;
Al Badawi, Ahmad ;
Bojja, Giridhar Reddy .
EXPERT SYSTEMS, 2022, 39 (10)
[7]   Meticulously Intelligent Identification System for Smart Grid Network Stability to Optimize Risk Management [J].
Abu Al-Haija, Qasem ;
Smadi, Abdallah A. ;
Allehyani, Mohammed F. .
ENERGIES, 2021, 14 (21)
[8]   High Performance Classification Model to Identify Ransomware Payments for Heterogeneous Bitcoin Networks [J].
Abu Al-Haija, Qasem ;
Alsulami, Abdulaziz A. .
ELECTRONICS, 2021, 10 (17)
[9]   On the Security of Cyber-Physical Systems Against Stochastic Cyber-Attacks Models [J].
Abu Al-Haija, Qasem .
2021 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2021, :155-160
[10]   An Efficient Deep-Learning-Based Detection and Classification System for Cyber-Attacks in IoT Communication Networks [J].
Abu Al-Haija, Qasem ;
Zein-Sabatto, Saleh .
ELECTRONICS, 2020, 9 (12) :1-26