Entropy and Divergence-based DDoS Attack Detection System in IoT Networks

被引:2
|
作者
Saiyed, Makhduma [1 ]
Al Anbagi, Irfan [1 ]
机构
[1] Univ Regina, Fac Engn & Appl Sci, Regina, SK S4S 0A2, Canada
关键词
DDoS attack; Entropy; Internet of things; KL divergence; Security;
D O I
10.1109/WiMob58348.2023.10187726
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
High and low-volume Distributed Denial of Service (DDoS) attacks are critical threats to many Internet of Things (IoT) networks. Low-volume attacks gradually overwhelm the device's resources, whereas high-volume attacks suddenly flood the device's resources, causing a decline in Quality of Service (QoS). Researchers have proposed various methods to detect DDoS attacks based on statistical and Machine Learning (ML) approaches. Research has also shown that statistical approaches are more efficient for IoT networks as they are simpler to develop and have better real-time performance. However, most existing ML and statistical-based detection methods are effective for either high-volume or low-volume attacks but not for both. This paper proposes a novel Entropy and Divergence-based DDoS Attack Detection (EDDAD) system that uses a statistical approach to simultaneously detect high and low-volume DDoS attacks with high accuracy. The EDDAD system computes entropy and Kullback-Leibler (KL) divergence of flow features in a time window to detect malicious traffic in IoT networks with adaptive thresholds that utilize statistical information. Our analysis of experimental results from a real testbed demonstrated that the EDDAD system is effective and can achieve detection accuracy of greater than 90% for both high and low-volume DDoS attacks.
引用
收藏
页码:224 / 230
页数:7
相关论文
共 50 条
  • [1] DDoS attack detection techniques in IoT networks: a survey
    Pakmehr, Amir
    Assmuth, Andreas
    Taheri, Negar
    Ghaffari, Ali
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (10): : 14637 - 14668
  • [2] An Entropy Based Approach for DDoS Attack Detection in IEEE 802.16 Based Networks
    Shojaei, Maryam
    Movahhedinia, Naser
    Ladani, Behrouz Tork
    [J]. ADVANCES IN INFORMATION AND COMPUTER SECURITY, 2011, 7038 : 129 - 143
  • [3] A Genetic Algorithm- and t-Test-Based System for DDoS Attack Detection in IoT Networks
    Saiyed, Makhduma F.
    Al-Anbagi, Irfan
    [J]. IEEE ACCESS, 2024, 12 : 25623 - 25641
  • [4] DDoS attack detection in IoT systems using Neural Networks
    Hekmati, Arvin
    [J]. PROCEEDINGS OF THE 2023 THE 22ND INTERNATIONAL CONFERENCE ON INFORMATION PROCESSING IN SENSOR NETWORKS, IPSN 2023, 2023, : 340 - 341
  • [5] Detection and Prevention Algorithm of DDoS Attack Over the IOT Networks
    Nsaif, Mohammed Ridha
    Abbood, Mohammed Falah
    Mahdi, Abbas Fadhil
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2020, 9 (03): : 899 - 906
  • [6] Federated Learning for Decentralized DDoS Attack Detection in IoT Networks
    Alhasawi, Yaser
    Alghamdi, Salem
    [J]. IEEE ACCESS, 2024, 12 : 42357 - 42368
  • [7] Multi-objective-based feature selection for DDoS attack detection in IoT networks
    Roopak, Monika
    Tian, Gui Yun
    Chambers, Jonathon
    [J]. IET NETWORKS, 2020, 9 (03) : 120 - 127
  • [8] DDoS attack detection algorithms based on entropy computing
    Li, Liying
    Zhou, Jianying
    Xiao, Ning
    [J]. INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2007, 4681 : 452 - +
  • [9] Flow and unified information-based DDoS attack detection system for multi-topology IoT networks
    Saiyed, Makhduma F.
    Al-Anbagi, Irfan
    [J]. INTERNET OF THINGS, 2023, 24
  • [10] Deep Ensemble Learning With Pruning for DDoS Attack Detection in IoT Networks
    Saiyedand, Makhduma F.
    Al-Anbagi, Irfan
    [J]. IEEE Transactions on Machine Learning in Communications and Networking, 2024, 2 : 596 - 616