Detecting Behavioral Change of IoT Devices Using Clustering-Based Network Traffic Modeling

被引:40
|
作者
Sivanathan, Arunan [1 ]
Gharakheili, Hassan Habibi [1 ]
Sivaraman, Vijay [1 ]
机构
[1] Univ New South Wales, Sch Elect Engn & Telecommun, Sydney, NSW 2052, Australia
来源
IEEE INTERNET OF THINGS JOURNAL | 2020年 / 7卷 / 08期
关键词
Clustering; Internet-of-Things (IoT) devices; traffic modeling; SYSTEMS;
D O I
10.1109/JIOT.2020.2984030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is increasingly becoming a major challenge for network administrators to manage connected devices and sensors ranging from smart lights to smoke alarms and security cameras, at scale. IoT devices use an extensive variety of firmware and provide little (or no) access for the management of their operating systems and configurations. Operators of the IoT infrastructure, therefore, need to employ traffic classification models (trained by historical data) to automatically detect their assets on the network and ensure the health of devices against cyber attacks by monitoring their network behavior. On the other hand, IoT manufacturers often automatically perform firmware upgrades from cloud servers to devices that are operational in the field. This can potentially lead to a change of device behavior which makes it difficult for network operators to maintain classification models (incorporating changes without retraining the entire model). In this article, we develop a modular device classification architecture that allows operators to automatically detect IoT devices by their network activity and dynamically accommodate legitimate changes in assets (either addition of new device profile or upgrade of existing profiles). Our contributions are threefold: 1) we identify key traffic attributes that can be obtained from flow-level network telemetry to characterize the behavior of various IoT device types. We develop an unsupervised one-class clustering method for each device to detect their normal network behavior; 2) we tune device-specific clustering models and use them to classify IoT devices from their network traffic in real time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering; and 3) we evaluate the efficacy of our scheme by applying it to traffic traces (benign and attack) from ten real IoT devices and demonstrate its ability to detect behavioral changes with an overall accuracy of more than 94 %.
引用
收藏
页码:7295 / 7309
页数:15
相关论文
共 50 条
  • [1] Adaptive Clustering-based Malicious Traffic Classification at the Network Edge
    Diallo, Alec F.
    Patras, Paul
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2021), 2021,
  • [2] Clustering of IoT Devices Using Device Profiling and Behavioral Analysis to Build Efficient Network Policies
    Hamza, Muhammad
    Geelani, Syed Mashhad M.
    Nawaz, Qamar
    Kabir, Asif
    Hamid, Isma
    [J]. MEHRAN UNIVERSITY RESEARCH JOURNAL OF ENGINEERING AND TECHNOLOGY, 2021, 40 (02) : 335 - 345
  • [3] A Clustering-Based Approach to Detecting Critical Traffic Road Segments in Urban Areas
    Kosanin, Ivan
    Gnjatovic, Milan
    Macek, Nemanja
    Joksimovic, Dusan
    [J]. AXIOMS, 2023, 12 (06)
  • [4] A New Combinatorial Characteristic Parameter for Clustering-Based Traffic Network Partitioning
    Liu, Duanyang
    Wang, Mengting
    Shen, Guojiang
    [J]. IEEE ACCESS, 2019, 7 : 40175 - 40182
  • [5] Network traffic analysis over clustering-based collective anomaly detection
    Wang, Chonghua
    Zhou, Hao
    Hao, Zhiqiang
    Hu, Shu
    Li, Jun
    Zhang, Xueying
    Jiang, Bo
    Chen, Xuehong
    [J]. COMPUTER NETWORKS, 2022, 205
  • [6] Novel Approach for Network Traffic Pattern Analysis using Clustering-based Collective Anomaly Detection
    Ahmed M.
    Mahmood A.N.
    [J]. Annals of Data Science, 2015, 2 (1) : 111 - 130
  • [7] Detecting Network Attacks using Federated Learning for IoT Devices
    Shahid, Osama
    Mothukuri, Viraaji
    Pouriyeh, Seyedamin
    Parizi, Reza M.
    Shahriar, Hossain
    [J]. 2021 IEEE 29TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP 2021), 2021,
  • [8] IoT Devices Discovery and Identification Using Network Traffic Data
    Feng, Yuzhou
    Deng, Liangdong
    Chen, Dong
    [J]. PROCEEDINGS OF THE 2019 CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS (WISEC '19), 2019, : 338 - 339
  • [9] Detecting Anomalous Network Traffic in IoT Networks
    Dang Hai Hoang
    Ha Duong Nguyen
    [J]. 2019 21ST INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ICT FOR 4TH INDUSTRIAL REVOLUTION, 2019, : 1143 - 1152
  • [10] Detecting IoT Malicious Traffic based on Autoencoder and Convolutional Neural Network
    Hwang, Ren-Hung
    Peng, Min-Chun
    Huang, Chien-Wei
    [J]. 2019 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2019,