A Construction of IoT Malicious Traffic Dataset and Its Applications
摘要
The current Internet of Things (IoT) malicious traffic dataset mainly relies on raw binary data at the traffic packet level and structured data at the session flow level for learning training and predictive classification, each of which has shortcomings and is not conducive to the construction of IoT malicious traffic classification models. In this paper, based on the packet and session stream datasets in the Iot-23 dataset, an importance-based feature extraction method is given, and a new malicious traffic dataset construction process is further proposed. The newly constructed malicious traffic dataset solves the shortcoming of mismatch between the number of features and the prediction performance in the traffic packet and session flow datasets. Experiments show that compared with a single dataset, the dataset constructed by the new method has richer and more important features, which improves the accuracy of malicious traffic classification and the generalization ability of the model, and is more conducive to the research of IoT malicious traffic classification.