Entropy and Divergence-based DDoS Attack Detection System in IoT Networks

被引:2
|
作者
Saiyed, Makhduma [1 ]
Al Anbagi, Irfan [1 ]
机构
[1] Univ Regina, Fac Engn & Appl Sci, Regina, SK S4S 0A2, Canada
关键词
DDoS attack; Entropy; Internet of things; KL divergence; Security;
D O I
10.1109/WiMob58348.2023.10187726
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
High and low-volume Distributed Denial of Service (DDoS) attacks are critical threats to many Internet of Things (IoT) networks. Low-volume attacks gradually overwhelm the device's resources, whereas high-volume attacks suddenly flood the device's resources, causing a decline in Quality of Service (QoS). Researchers have proposed various methods to detect DDoS attacks based on statistical and Machine Learning (ML) approaches. Research has also shown that statistical approaches are more efficient for IoT networks as they are simpler to develop and have better real-time performance. However, most existing ML and statistical-based detection methods are effective for either high-volume or low-volume attacks but not for both. This paper proposes a novel Entropy and Divergence-based DDoS Attack Detection (EDDAD) system that uses a statistical approach to simultaneously detect high and low-volume DDoS attacks with high accuracy. The EDDAD system computes entropy and Kullback-Leibler (KL) divergence of flow features in a time window to detect malicious traffic in IoT networks with adaptive thresholds that utilize statistical information. Our analysis of experimental results from a real testbed demonstrated that the EDDAD system is effective and can achieve detection accuracy of greater than 90% for both high and low-volume DDoS attacks.
引用
收藏
页码:224 / 230
页数:7
相关论文
共 50 条
  • [41] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    [J]. CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [42] DDoS Attack Detection Method Based on Improved KNN With the Degree of DDoS Attack in Software-Defined Networks
    Dong, Shi
    Sarem, Mudar
    [J]. IEEE ACCESS, 2020, 8 : 5039 - 5048
  • [43] Joint Entropy Analysis Model for DDoS Attack Detection
    Rahmani, Hamza
    Sahli, Nabil
    Kammoun, Farouk
    [J]. FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 267 - 271
  • [44] Cusum - Entropy: An efficient method for DDoS attack detection
    Ozcelik, Ilker
    Brooks, Richard R.
    [J]. 2016 4TH INTERNATIONAL ISTANBUL SMART GRID CONGRESS AND FAIR (ICSG), 2016, : 85 - 89
  • [45] Towards a machine learning-based framework for DDOS attack detection in software-defined IoT (SD-IoT) networks
    Bhayo, Jalal
    Shah, Syed Attique
    Hameed, Sufian
    Ahmed, Awais
    Nasir, Jamal
    Draheim, Dirk
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 123
  • [46] Performance analysis of entropy variation-based detection of DDoS attacks in IoT
    Pandey, Nimisha
    Mishra, Pramod Kumar
    [J]. INTERNET OF THINGS, 2023, 23
  • [47] An Entropy-based DDoS attack Detection and Classification with Hierarchical Temporal Memory
    Nguyen, Manh Hung
    Yu-Kuen Lai
    Kai-Po Chang
    [J]. 2021 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2021, : 1942 - 1948
  • [48] A DDoS Attack Detection Method Based on Information Entropy and Deep Learning in SDN
    Wang, Lu
    Liu, Ying
    [J]. PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 1084 - 1088
  • [49] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Shanshan Yu
    Jicheng Zhang
    Ju Liu
    Xiaoqing Zhang
    Yafeng Li
    Tianfeng Xu
    [J]. EURASIP Journal on Wireless Communications and Networking, 2021
  • [50] A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic
    Tian, Qiwen
    Miyata, Sumiko
    [J]. IOT, 2023, 4 (02): : 95 - 111