Hybrid approach to intrusion detection in fog-based IoT environments

被引:77
|
作者
de Souza, Cristiano Antonio [1 ]
Westphall, Carlos Becker [2 ]
Machado, Renato Bobsin [3 ]
Mangueira Sobral, Joao Bosco [2 ]
Vieira, Gustavo dos Santos [4 ]
机构
[1] Univ Fed Santa Catarina, Comp Sci, Florianopolis, SC, Brazil
[2] Univ Fed Santa Catarina, Florianopolis, SC, Brazil
[3] State Univ Western Parana, Grad Program Elect & Comp Engin PGEEC, Foz Do Iguacu, Parana, Brazil
[4] State Univ Western Parana, Foz Do Iguacu, Parana, Brazil
关键词
Internet of things; Intrusion detection; Fog computing; Machine learning; DEEP LEARNING APPROACH; NEURAL-NETWORK; INTERNET; OPTIMIZATION; HYPERGRAPH; FRAMEWORK; IDS;
D O I
10.1016/j.comnet.2020.107417
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In the Internet of Things (IoT) systems, information of various kinds is continuously captured, processed, and transmitted by systems generally interconnected by the Internet and distributed solutions. Attacks to capture information and overload services are common. This fact makes security techniques indispensable in IoT en-vironments. Intrusion detection is one of the vital security points, aimed at identifying attempted attacks. The characteristics of IoT devices make it impossible to apply these solutions in this environment. Also, the existing anomaly-based methods for multiclass detection do not present acceptable accuracy. We present an intrusion detection architecture that operates in the fog computing layer. It has two steps and aims to classify events into specific types of attacks or non-attacks, for the execution of countermeasures. Our work presents a relevant con-tribution to the state of the art in this aspect. We propose a hybrid binary classification method called DNN-kNN. It has high accuracy and recall rates and is ideal for composing the first level of the two-stage detection method of the presented architecture. The approach is based on Deep Neural Networks (DNN) and the k-Nearest Neighbor (kNN) algorithm. It was evaluated with the public databases NSL-KDD and CICIDS2017. We used the method of selecting attributes based on the rate of information gain. The approach proposed in this work obtained 99.77% accuracy for the NSL-KDD dataset and 99.85% accuracy for the CICIDS2017 dataset. The experimental results showed that the proposed hybrid approach was able to achieve greater precision about classic machine learning approaches and the recent advances in intrusion detection for IoT systems. In addition, the approach works with low overhead in terms of memory and processing costs.
引用
下载
收藏
页数:18
相关论文
共 50 条
  • [31] Fog-Based Distributed Intrusion Detection System Against False Metering Attacks in Smart Grid
    Chekired, Djabir Abdeldjalil
    Khoukhi, Lyes
    Mouftah, Hussein T.
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [32] Fog-based Federated Time Series Forecasting for IoT Data
    Sharma, Mradula
    Kaur, Parmeet
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (02)
  • [33] A Fog-Based Digital Forensics Investigation Framework for IoT Systems
    Al-Masri, Eyhab
    Bai, Yan
    Li, Juan
    2018 IEEE INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD), 2018, : 196 - 201
  • [34] Fog-Based Computing and Storage Offloading for Data Synchronization in IoT
    Wang, Tian
    Zhou, Jiyuan
    Liu, Anfeng
    Bhuiyan, Md Zakirul Alam
    Wang, Guojun
    Jia, Weijia
    IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (03) : 4272 - 4282
  • [35] Towards Reliable IoT: Fog-Based AI Sensor Validation
    Russell, Luke
    Goubran, Rafik
    Kwamena, Felix
    2019 3RD IEEE INTERNATIONAL CONFERENCE ON CLOUD AND FOG COMPUTING TECHNOLOGIES AND APPLICATIONS (IEEE CLOUD SUMMIT 2019), 2019, : 37 - 44
  • [36] Fog-Based Detection for Random-Access IoT Networks with Per-Measurement Preambles
    Kassab, Rahif
    Simeone, Osvaldo
    Popovski, Petar
    PROCEEDINGS OF THE 21ST IEEE INTERNATIONAL WORKSHOP ON SIGNAL PROCESSING ADVANCES IN WIRELESS COMMUNICATIONS (IEEE SPAWC2020), 2020,
  • [37] Fog Computing-Based Intrusion Detection Architecture to Protect IoT Networks
    Labiod, Yasmine
    Korba, Abdelaziz Amara
    Ghoualmi, Nacira
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 125 (01) : 231 - 259
  • [38] Fog Computing-Based Intrusion Detection Architecture to Protect IoT Networks
    Yasmine Labiod
    Abdelaziz Amara Korba
    Nacira Ghoualmi
    Wireless Personal Communications, 2022, 125 : 231 - 259
  • [39] A novel hybrid calibration method for FOG-based IMU
    Xu, Bo
    Wang, Lianzhao
    Duan, Tenghui
    MEASUREMENT, 2019, 147
  • [40] PyFF: A Fog-Based Flexible Architecture for Enabling Privacy-by-Design IoT-Based Communal Smart Environments
    Benhamida, Fatima Zohra
    Navarro, Joan
    Gomez-Carmona, Oihane
    Casado-Mansilla, Diego
    Lopez-de-Ipina, Diego
    Zaballos, Agustin
    SENSORS, 2021, 21 (11)