Correlation-Aware Neural Networks for DDoS Attack Detection in IoT Systems

被引:0
|
作者
Hekmati, Arvin [1 ]
Zhang, Jiahe [2 ]
Sarkar, Tamoghna [2 ]
Jethwa, Nishant [1 ]
Grippo, Eugenio [2 ]
Krishnamachari, Bhaskar [1 ,2 ]
机构
[1] Univ Southern Calif, Dept Comp Sci, Los Angeles, CA 90007 USA
[2] Univ Southern Calif, Dept Elect & Comp Engn, Los Angeles, CA 90007 USA
关键词
Internet of Things; Peer-to-peer computing; Denial-of-service attack; Computer crime; Servers; Correlation; Neural networks; IoT DDoS attacks; datasets; neural networks; machine learning; botnet; Cauchy distribution; MACHINE; MECHANISMS;
D O I
10.1109/TNET.2024.3408675
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We present a comprehensive study on applying machine learning to detect distributed Denial of service (DDoS) attacks using large-scale Internet of Things (IoT) systems. While prior works and existing DDoS attacks have largely focused on individual nodes transmitting packets at a high volume, we investigate more sophisticated futuristic attacks that use large numbers of IoT devices and camouflage their attack by having each node transmit at a volume typical of benign traffic. We introduce new correlation-aware architectures that take into account the correlation of traffic across IoT nodes. We extensively analyze the proposed architectures by evaluating five different neural network models trained on a dataset derived from a 4060-node real-world IoT system. We observe that long short-term memory (LSTM) and a transformer-based model, in conjunction with the architectures that use correlation information of the IoT nodes, provide higher performance (in terms of F1 score and binary accuracy) than the other models and architectures, especially when the attacker camouflages itself by following benign traffic distribution on each transmitting node. For instance, by using the LSTM model, the distributed correlation-aware architecture gives 81% F1 score for the attacker that camouflages their attack with benign traffic as compared to 35% for the architecture that does not use correlation information. We validate the effectiveness of our proposed detection mechanism by implementing it on a real testbed. We also investigate the performance of heuristics for selecting a subset of nodes to share their data for correlation-aware architectures to meet resource constraints.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Demo Abstract: CUDDoS - Correlation-aware Ubiquitous Detection of DDoS in IoT Systems
    Zhang, Jiahe
    Sarkar, Tamoghna
    Hekmati, Arvin
    Krishnamachari, Bhaskar
    [J]. PROCEEDINGS OF THE 21ST ACM CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS, SENSYS 2023, 2023, : 482 - 483
  • [2] DDoS attack detection in IoT systems using Neural Networks
    Hekmati, Arvin
    [J]. PROCEEDINGS OF THE 2023 THE 22ND INTERNATIONAL CONFERENCE ON INFORMATION PROCESSING IN SENSOR NETWORKS, IPSN 2023, 2023, : 340 - 341
  • [3] Neural Networks for DDoS Attack Detection using an Enhanced Urban IoT Dataset
    Hekmati, Arvin
    Grippo, Eugenio
    Krishnamachari, Bhaskar
    [J]. 2022 31ST INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2022), 2022,
  • [4] DDoS attack detection techniques in IoT networks: a survey
    Pakmehr, Amir
    Assmuth, Andreas
    Taheri, Negar
    Ghaffari, Ali
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (10): : 14637 - 14668
  • [5] Detection and Prevention Algorithm of DDoS Attack Over the IOT Networks
    Nsaif, Mohammed Ridha
    Abbood, Mohammed Falah
    Mahdi, Abbas Fadhil
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2020, 9 (03): : 899 - 906
  • [6] Federated Learning for Decentralized DDoS Attack Detection in IoT Networks
    Alhasawi, Yaser
    Alghamdi, Salem
    [J]. IEEE ACCESS, 2024, 12 : 42357 - 42368
  • [7] Deep Ensemble Learning With Pruning for DDoS Attack Detection in IoT Networks
    Saiyedand, Makhduma F.
    Al-Anbagi, Irfan
    [J]. IEEE Transactions on Machine Learning in Communications and Networking, 2024, 2 : 596 - 616
  • [8] Neural Prefiltering for Correlation-Aware Levels of Detail
    Weier, Philippe
    Zirr, Tobias
    Kaplanyan, Anton
    Yan, Ling-Qi
    Slusallek, Philipp
    [J]. ACM TRANSACTIONS ON GRAPHICS, 2023, 42 (04):
  • [9] Entropy and Divergence-based DDoS Attack Detection System in IoT Networks
    Saiyed, Makhduma
    Al Anbagi, Irfan
    [J]. 2023 19TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS, WIMOB, 2023, : 224 - 230
  • [10] Anomaly detection framework to prevent DDoS attack in fog empowered IoT networks
    Sharma, Deepak Kumar
    Dhankhar, Tarun
    Agrawal, Gaurav
    Singh, Satish Kumar
    Gupta, Deepak
    Nebhen, Jamel
    Razzak, Imran
    [J]. AD HOC NETWORKS, 2021, 121