...
首页> 外文期刊>Internet of Things Journal, IEEE >A Supervised Intrusion Detection System for Smart Home IoT Devices
【24h】

A Supervised Intrusion Detection System for Smart Home IoT Devices

机译:智能家居物联网设备的监督入侵检测系统

获取原文
获取原文并翻译 | 示例

摘要

The proliferation in Internet of Things (IoT) devices, which routinely collect sensitive information, is demonstrated by their prominence in our daily lives. Although such devices simplify and automate every day tasks, they also introduce tremendous security flaws. Current insufficient security measures employed to defend smart devices make IoT the "weakest" link to breaking into a secure infrastructure, and therefore an attractive target to attackers. This paper proposes a three layer intrusion detection system (IDS) that uses a supervised approach to detect a range of popular network based cyber-attacks on IoT networks. The system consists of three main functions: 1) classify the type and profile the normal behavior of each IoT device connected to the network; 2) identifies malicious packets on the network when an attack is occurring; and 3) classifies the type of the attack that has been deployed. The system is evaluated within a smart home testbed consisting of eight popular commercially available devices. The effectiveness of the proposed IDS architecture is evaluated by deploying 12 attacks from 4 main network based attack categories, such as denial of service (DoS), man-in-the-middle (MITM)/spoofing, reconnaissance, and replay. Additionally, the system is also evaluated against four scenarios of multistage attacks with complex chains of events. The performance of the system's three core functions result in an F-measure of: 1) 96.2%; 2) 90.0%; and 3) 98.0%. This demonstrates that the proposed architecture can automatically distinguish between IoT devices on the network, whether network activity is malicious or benign, and detect which attack was deployed on which device connected to the network successfully.
机译:日常收集敏感信息的物联网(IoT)设备的普及体现在其日常生活中。尽管此类设备简化并自动化了日常任务,但它们也引入了巨大的安全漏洞。当前用于防御智能设备的安全措施不足,使得IoT成为侵入安全基础架构的“最弱”链接,因此成为攻击者的诱人目标。本文提出了一种三层入侵检测系统(IDS),该系统使用一种受监督的方法来检测IoT网络上一系列基于网络的流行网络攻击。该系统包括三个主要功能:1)分类类型并描述连接到网络的每个IoT设备的正常行为; 2)在攻击发生时识别网络上的恶意数据包;和3)对已经部署的攻击类型进行分类。该系统在由八种流行的商用设备组成的智能家居测试平台中进行评估。通过从4种主要的基于网络的攻击类别(例如拒绝服务(DoS),中间人(MITM)/欺骗,侦察和重播)部署12种攻击,可以评估提出的IDS体系结构的有效性。此外,还针对具有复杂事件链的四种多阶段攻击方案对系统进行了评估。系统的三个核心功能的性能导致F度量为:1)96.2%; 2)90.0%; 3)98.0%。这证明了所提出的架构可以自动区分网络上的IoT设备(网络活动是恶意的还是良性的),并检测在成功连接到网络的哪个设备上部署了哪种攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号