Efficient and Intelligent Attack Detection in Software Defined IoT Networks

被引:14
|
作者
Zhang, Yuntong [1 ]
Xu, Jingye [2 ]
Wang, Zhiwei [2 ]
Geng, Rong [1 ]
Choo, Kim-Kwang Raymond [1 ,2 ,3 ]
Arturo Perez-Diaz, Jesus [4 ]
Zhu, Dakai [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Univ Texas San Antonio, Dept Elect & Comp Engn, San Antonio, TX USA
[3] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX USA
[4] Tecnol Monterrey, Escuela Ingn & Ciencias, Monterrey, NL, Mexico
关键词
INTRUSION DETECTION; INTERNET; SECURE; THINGS;
D O I
10.1109/icess49830.2020.9301591
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increasing deployment of Internet of Things (IoT) in various domains (e.g., smart buildings and critical infrastructure protection), the limited capabilities on such devices introduce significant security vulnerabilities, especially when considering their integration with Software Defined Network (SDN) to provide flexible services. In this paper, we investigate efficient attack detection techniques for such software-defined IoT (SD-IoT) networks. First, we simulate commonly utilized attacks, such as SYN, ping flood, UDP port scan and UDP flood, using Mininet-WiFi for a given SD-IoT topology and collect representative datasets with Wireshark. Then, focusing on Random Forest (RF) machine learning models, we study the effects of various feature sets (e.g., IPs and ports) on the detection accuracy for different attacks. Moreover, the effects of RF configurations (i.e., forest size and tree depth) on the detection accuracy and run-time overheads are also evaluated. In addition to our collected datasets, two known IoT datasets were also used. The results show that RF can achieve high detection accuracy with the selected feature sets for the considered attacks. Moreover, the detection accuracy of RF decreases only slightly with reduced forest sizes (e.g., fewer trees or less depth) where the run-time overheads can be significantly reduced. This demonstrates the utility of the studied techniques in resource-constrained IoT networks.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] An Efficient Counter-Based DDoS Attack Detection Framework Leveraging Software Defined IoT (SD-IoT)
    Bhayo, Jalal
    Hameed, Sufian
    Shah, Syed Attique
    [J]. IEEE ACCESS, 2020, 8 : 221612 - 221631
  • [2] A Deep CNN Ensemble Framework for Efficient DDoS Attack Detection in Software Defined Networks
    Haider, Shahzeb
    Akhunzada, Adnan
    Mustafa, Iqra
    Patel, Tanil Bharat
    Fernandez, Amanda
    Choo, Kim-Kwang Raymond
    Iqbal, Javed
    [J]. IEEE ACCESS, 2020, 8 : 53972 - 53983
  • [3] An intelligent energy efficient optimized approach to control the traffic flow in Software-Defined IoT networks
    Keshari, Surendra Kumar
    Kansal, Vineet
    Kumar, Sumit
    Bansal, Priti
    [J]. SUSTAINABLE ENERGY TECHNOLOGIES AND ASSESSMENTS, 2023, 55
  • [4] Overview of DDoS Attack Detection in Software-Defined Networks
    Wang, Heyu
    Li, Yixuan
    [J]. IEEE ACCESS, 2024, 12 : 38351 - 38381
  • [5] Attack detection and mitigation using Intelligent attack graph model for Forensic in IoT Networks
    Bhardwaj, Sonam
    Dave, Mayank
    [J]. TELECOMMUNICATION SYSTEMS, 2024, 85 (04) : 601 - 621
  • [6] Attack detection and mitigation using Intelligent attack graph model for Forensic in IoT Networks
    Sonam Bhardwaj
    Mayank Dave
    [J]. Telecommunication Systems, 2024, 85 : 601 - 621
  • [7] Computer detection intelligent mining algorithm for software defined networks
    Hao, Yaping
    Fu, Yanwei
    [J]. PHYSICAL COMMUNICATION, 2024, 63
  • [8] Towards a machine learning-based framework for DDOS attack detection in software-defined IoT (SD-IoT) networks
    Bhayo, Jalal
    Shah, Syed Attique
    Hameed, Sufian
    Ahmed, Awais
    Nasir, Jamal
    Draheim, Dirk
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 123
  • [9] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    [J]. IEEE ACCESS, 2020, 8 : 132502 - 132513
  • [10] Edge DDoS Attack Detection Method Based on Software Defined Networks
    Ren, Gangsheng
    Zhang, Yang
    Zhang, Shukui
    Long, Hao
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 597 - 611