An unsupervised approach for the detection of zero-day distributed denial of service attacks in Internet of Things networks

被引:0
|
作者
Roopak, Monika [1 ]
Parkinson, Simon [2 ]
Tian, Gui Yun [3 ]
Ran, Yachao [3 ]
Khan, Saad [2 ]
Chandrasekaran, Balasubramaniyan [4 ]
机构
[1] Univ Bedfordshire, Luton, Beds, England
[2] Univ Huddersfield, Huddersfield, England
[3] Newcastle Univ, Newcastle Upon Tyne, England
[4] Florida Polytech Univ, Lakeland, FL USA
关键词
computer network security; Internet of Things; unsupervised learning;
D O I
10.1049/ntw2.12134
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The authors introduce an unsupervised Intrusion Detection System designed to detect zero-day distributed denial of service (DDoS) attacks in Internet of Things (IoT) networks. This system can identify anomalies without needing prior knowledge or training on attack information. Zero-day attacks exploit previously unknown vulnerabilities, making them hard to detect with traditional deep learning and machine learning systems that require pre-labelled data. Labelling data is also a time-consuming task for security experts. Therefore, unsupervised methods are necessary to detect these new threats. The authors focus on DDoS attacks, which have recently caused significant financial and service disruptions for many organisations. As IoT networks grow, these attacks become more sophisticated and harmful. The proposed approach detects zero-day DDoS attacks by using random projection to reduce data dimensionality and an ensemble model combining K-means, Gaussian mixture model, and one-class SVM with a hard voting technique for classification. The method was evaluated using the CIC-DDoS2019 dataset and achieved an accuracy of 94.55%, outperforming other state-of-the-art unsupervised learning methods. An unsupervised ensemble model for the detection of the distributed denial of service attacks in Internet of Things systems. image
引用
收藏
页码:513 / 527
页数:15
相关论文
共 50 条
  • [11] Detection of zero-day attacks in computer networks using combined classification
    Gavari Bami, Hamid
    Moharamkhani, Elaheh
    Zadmehr, Behrouz
    Najafpoor, Vahid
    Shokouhifar, Mohammad
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (27):
  • [12] A Brief Review of Unsupervised Learning Algorithms for Zero-Day Attacks in Intrusion Detection Systems
    Oluwadare, Sunkanmi
    ElSayed, Zag
    Adekoya, Oluwaseun
    2024 IEEE 3RD INTERNATIONAL CONFERENCE ON COMPUTING AND MACHINE INTELLIGENCE, ICMI 2024, 2024,
  • [13] Collaborative Blockchain-Based Detection of Distributed Denial of Service Attacks Based on Internet of Things Botnets
    Spathoulas, Georgios
    Giachoudis, Nikolaos
    Damiris, Georgios-Paraskevas
    Theodoridis, Georgios
    FUTURE INTERNET, 2019, 11 (11):
  • [14] Detection of Distributed Denial of Service Attacks in Software Defined Networks
    Barki, Lohit
    Shidling, Amrit
    Meti, Nisharani
    Narayan, D. G.
    Mulla, Mohammed Moin
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 2576 - 2581
  • [15] Internet of Things and Distributed Denial of Service Mitigation
    Ali, Mohammed AlSaudi
    Motawa, Dyaa
    Al-Harby, Fahad
    ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 26 - 36
  • [16] Detection of distributed denial of service attacks using statistical pre-processor and unsupervised neural networks
    Jalili, R
    Imani-Mehr, F
    Amini, M
    Shahriari, HR
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, 2005, 3439 : 192 - 203
  • [17] REATO: REActing TO Denial of Service attacks in the Internet of Things
    Sicari, Sabrina
    Rizzardi, Alessandra
    Miorandi, Daniele
    Coen-Porisini, Alberto
    COMPUTER NETWORKS, 2018, 137 : 37 - 48
  • [18] Internet-of-Things Security : Denial of Service Attacks
    Aris, Ahmet
    Oktug, Sema F.
    Yalcin, Siddika Berna Ors
    2015 23RD SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2015, : 903 - 906
  • [19] An integrated approach explaining the detection of distributed denial of service attacks
    Batchu, Raj Kumar
    Seetha, Hari
    COMPUTER NETWORKS, 2022, 216
  • [20] Sophistication in distributed denial-of-service attacks on the Internet
    Kumar, VA
    CURRENT SCIENCE, 2004, 87 (07): : 885 - 888