<p>Network Intrusion Detection Systems (NIDS) are vital for the security of modern networks, especially for networks that contain vulnerable IoT devices. While NIDS can use robust artificial intelligence (AI) / machine learning (ML)-based network traffic classifiers to better recognize and defend against traffic that represents network attacks and intrusions, these models exhibit black-box behaviors and thus the security of these AI/ML-based security mechanism is largely unknown. This research investigates the impacts of adversarial IoT NetFlow traffic crafted using perturbations generated by a custom variant of the Fast Gradient Signed Method on a CNN-based network traffic classifier. This research also creates a novel, custom tool for visualizing these adversarial traffic examples using statistical tools and various visualizers. The resulting tool, IoT VisPerNet, aids in explaining how these adversarial perturbations on IoT NetFlow traffic are effective. Our experiments generate templates of adversarial IoT network traffic that can be studied to learn the weaknesses of machine learning classifiers. The results from this research’s perturbation algorithm show promise in fooling the traffic classifier but require improvement to be more fine-grained. Further, IoT VisPerNet is effective in highlighting certain features in the IoT network traffic that greatly affect traffic classification for different attack classes.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

IoT VisPerNet: Adversarial Perturbation Visualization for IoT Networks

  • Jonathan Gregory,
  • Jacob Auerbach,
  • Qi Liao

摘要

Network Intrusion Detection Systems (NIDS) are vital for the security of modern networks, especially for networks that contain vulnerable IoT devices. While NIDS can use robust artificial intelligence (AI) / machine learning (ML)-based network traffic classifiers to better recognize and defend against traffic that represents network attacks and intrusions, these models exhibit black-box behaviors and thus the security of these AI/ML-based security mechanism is largely unknown. This research investigates the impacts of adversarial IoT NetFlow traffic crafted using perturbations generated by a custom variant of the Fast Gradient Signed Method on a CNN-based network traffic classifier. This research also creates a novel, custom tool for visualizing these adversarial traffic examples using statistical tools and various visualizers. The resulting tool, IoT VisPerNet, aids in explaining how these adversarial perturbations on IoT NetFlow traffic are effective. Our experiments generate templates of adversarial IoT network traffic that can be studied to learn the weaknesses of machine learning classifiers. The results from this research’s perturbation algorithm show promise in fooling the traffic classifier but require improvement to be more fine-grained. Further, IoT VisPerNet is effective in highlighting certain features in the IoT network traffic that greatly affect traffic classification for different attack classes.