<p>The Internet of Things (IoT) is critically prone to Denial of Service (DoS) attacks at multiple layers. If designed carefully, intrusion detection systems (IDS) can detect these attacks effectively. In the proposed study, we develop a Hybrid IDS to detect Cross-Layer DoS attacks in IoT. The proposed Cross-Layer system reduces the false positive rate considerably than a single IDS. The IDS is designed by ensembling multiple machine learning techniques to avoid overfitting or underfitting. The Hybrid IDS works in two stages, the first stage for detection of the attack occurrence (Anomaly detection) followed by a second stage to classify the attack types (Signature of the attacks). The output of the first stage is Correctly Detected Samples (CDS), which are again tested by the second stage to get Correctly Classified Samples (CCS). Another unique aspect of the proposed study is the dataset generation for different attacks considered. Rather than using the existing dataset, we have developed a trace file in NetSim Simulator by designing an attack environment. At the same time, during the feature selection process, a novel and efficient technique is applied to select the best feature set along with the critical component (CF). Simulation results accurately detect CDS of up to 95% and CCS of up to 96% with a weighted average F1 score. The testing time of the proposed model is also considerably lower than that of individual models, which makes the system efficient and lightweight.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Hybrid Intrusion Detection System for detecting Cross-layer DoS attacks in IoT

  • Aditi Paul,
  • Somnath Sinha,
  • Saumya Mishra

摘要

The Internet of Things (IoT) is critically prone to Denial of Service (DoS) attacks at multiple layers. If designed carefully, intrusion detection systems (IDS) can detect these attacks effectively. In the proposed study, we develop a Hybrid IDS to detect Cross-Layer DoS attacks in IoT. The proposed Cross-Layer system reduces the false positive rate considerably than a single IDS. The IDS is designed by ensembling multiple machine learning techniques to avoid overfitting or underfitting. The Hybrid IDS works in two stages, the first stage for detection of the attack occurrence (Anomaly detection) followed by a second stage to classify the attack types (Signature of the attacks). The output of the first stage is Correctly Detected Samples (CDS), which are again tested by the second stage to get Correctly Classified Samples (CCS). Another unique aspect of the proposed study is the dataset generation for different attacks considered. Rather than using the existing dataset, we have developed a trace file in NetSim Simulator by designing an attack environment. At the same time, during the feature selection process, a novel and efficient technique is applied to select the best feature set along with the critical component (CF). Simulation results accurately detect CDS of up to 95% and CCS of up to 96% with a weighted average F1 score. The testing time of the proposed model is also considerably lower than that of individual models, which makes the system efficient and lightweight.