<p>Efficient botnet detection is of great security importance and has been the focus of researchers in recent years. Botnet detection is also a difficult task due to the difficulty in distinguishing it from normal traffic. At the same time, detecting these botnets require a lot of computation resources using traditional methods and this limitation makes it even more difficult to detect them on Internet of Things (IoT) devices. Considering the massive IoT data, an efficient and lightweight approach for detecting and predicting IoT botnet attacks is required. In this paper, multiple lightweight machine learning methods including a deep Multilayer Perceptron (MLP) method and a Random Forest (RF) method are integrated into a stacked ensemble learning model to detect botnet attacks in IoT devices. This integration is based on applying lasso regression on features and utilizing a logistic regression in ensemble learning, which leads to increasing the accuracy of botnet detection and reducing its computational complexity. The performance evaluation of the proposed model is examined from two perspectives: accuracy and lightweight characteristics; and for this purpose, a real-world UNSW (BoT-IoT) dataset is used. A comparative study with competitive neural network methods demonstrates that our approach delivers a better outcome. Experimental results reveal that this method has a higher efficiency in all metrics than competing methods including accuracy, precision, recall, and F1 score with values of 99.3%, 99.2%, 99%, and 99.1%, respectively. Besides, the results showed that the proposed method requires at least 36% less CPU and 38% less memory compared to the competing methods, which makes the proposed method to be suitable for IoT devises with limited resources.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A lightweight and efficient model for botnet detection in IoT using stacked ensemble learning

  • Rasool Esmaeilyfard,
  • Zohre Shoaei,
  • Reza Javidan

摘要

Efficient botnet detection is of great security importance and has been the focus of researchers in recent years. Botnet detection is also a difficult task due to the difficulty in distinguishing it from normal traffic. At the same time, detecting these botnets require a lot of computation resources using traditional methods and this limitation makes it even more difficult to detect them on Internet of Things (IoT) devices. Considering the massive IoT data, an efficient and lightweight approach for detecting and predicting IoT botnet attacks is required. In this paper, multiple lightweight machine learning methods including a deep Multilayer Perceptron (MLP) method and a Random Forest (RF) method are integrated into a stacked ensemble learning model to detect botnet attacks in IoT devices. This integration is based on applying lasso regression on features and utilizing a logistic regression in ensemble learning, which leads to increasing the accuracy of botnet detection and reducing its computational complexity. The performance evaluation of the proposed model is examined from two perspectives: accuracy and lightweight characteristics; and for this purpose, a real-world UNSW (BoT-IoT) dataset is used. A comparative study with competitive neural network methods demonstrates that our approach delivers a better outcome. Experimental results reveal that this method has a higher efficiency in all metrics than competing methods including accuracy, precision, recall, and F1 score with values of 99.3%, 99.2%, 99%, and 99.1%, respectively. Besides, the results showed that the proposed method requires at least 36% less CPU and 38% less memory compared to the competing methods, which makes the proposed method to be suitable for IoT devises with limited resources.