<p>With the growth in IoT networks, both in usage and the number of devices, considerable challenges appear in the field. The majority of the past research is focused on analyzing traffic on the destination (victim’s) side which has some major drawbacks. That is, they are only passive defenses after the attack and do not use the outbound statistical features of attacks. Therefore, it is hard to trace back to the attacker with these approaches. In this paper, we focused on analyzing the inner botnet traffic from the attacker’s source network which allows us to detect and prevent Distributed Denial of Service (DDoS) attacks more efficiently. The novelty of the work is the prevention of DDoS attacks by detecting the initial phase of the attack before it harms the victim. We use attention-based deep learning models to better analyze the sequence of traffic exchange among bots (within the source network). This results in stopping the attack from the origin before it begins. We compared our method with some previous machine learning models on the BOT-IoT dataset which is real data gathered by the University of New South Wales (UNSW) research center. The results show that using the attention mechanism will increase the F1-score significantly to 99.5%.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DDos prevention in IoT networks by analyzing source-side inter-bot traffic using deep learning techniques

  • Saba Malekzadeh,
  • Saleh Yousefi,
  • Mir Saman Tajbakhsh

摘要

With the growth in IoT networks, both in usage and the number of devices, considerable challenges appear in the field. The majority of the past research is focused on analyzing traffic on the destination (victim’s) side which has some major drawbacks. That is, they are only passive defenses after the attack and do not use the outbound statistical features of attacks. Therefore, it is hard to trace back to the attacker with these approaches. In this paper, we focused on analyzing the inner botnet traffic from the attacker’s source network which allows us to detect and prevent Distributed Denial of Service (DDoS) attacks more efficiently. The novelty of the work is the prevention of DDoS attacks by detecting the initial phase of the attack before it harms the victim. We use attention-based deep learning models to better analyze the sequence of traffic exchange among bots (within the source network). This results in stopping the attack from the origin before it begins. We compared our method with some previous machine learning models on the BOT-IoT dataset which is real data gathered by the University of New South Wales (UNSW) research center. The results show that using the attention mechanism will increase the F1-score significantly to 99.5%.