Cyber Attack Detection in IoT Using Enhanced Stream Classification Algorithm
摘要
The Internet of Things (IoT) has been a part of the world today, meanwhile, the protection of increasing numbers of IoT devices against cyber threats is a rising concern. Although Artificial Intelligence (AI) based Intrusion Detection System (IDS) has been developed to detect cyber attacks in IoT, the frequently changing nature of data streams, e.g., the impacts of concept drift, adds more complexity to this challenge. One typical case is when there is a delay in verifying new data, i.e., no new labeled data, besides a limited amount of labeled data for initialization, is available to train or update the AI-based IDS with extreme verification latency (EVL). The Stream Classification Algorithm Guided by Clustering (SCARGC) is recognized for effectively allowing AI models to navigate and learn among these data steams during EVL scenarios. In this work, we aim to evaluate the performance of SCARGC and refine its capabilities by introducing an enhanced SCARGC (eSCARGC) with an improved clustering approach to boost learning performance. Real-world IoT cyberattack data in an open dataset has been used for evaluation. The evaluation results demonstrate that our proposed eSCARGC outperforms SCARGC with an improved performance, allowing AI-based IDS to function under EVL scenarios in IoT.