Deep Learning Model to Detect HTTP-Based Attack on Internet of Things
摘要
The information exchange between devices and remote servers occurs through the Application Programming Interface (API), which was created based on Internet technology (commonly referred to as web technology), in most of edge computing applications, including Internet of Things (IoT) devices. The majority of users cannot use the edge device APIs directly; hence, they experience relatively fewer threats than users of typical web applications. However, as IoT devices have gained popularity, attacks targeting APIs have started to acquire attraction. In order to identify online traffic received by IoT services and mine dangerous traffic, this paper provides a web attack vector identification approach that will deliver security information to the Security Operation Center (SOC). This approach is based on the feature extraction, targeting the mostly constant message format of the API request, in combination with the Bidirectional Long Short-Term Memory (BLSTM) attack vector identification for online traffic. The experimental findings demonstrate that, in comparison to standard machine learning approaches and rule-based web application firewalls (WAF), the suggested approach is more successful at identifying attacks against IoT service APIs.