IoTEnsemble: Detection of Botnet Attacks on Internet of Things

Ruoyu Li, Qing Li, Yucheng Huang, Wenbin Zhang, Peican Zhu, Yong Jiang

科研成果: 书/报告/会议事项章节会议稿件同行评审

7 引用 (Scopus)

摘要

As the Internet of Things (IoT) plays an increasingly important role in real life, the concern about IoT malware and botnet attacks is considerably growing. Meanwhile, with new techniques such as edge computing and artificial intelligence applied to IoT networks, these devices nowadays become more functional than ever before, which challenges many existing network anomaly detection systems due to the lack of generalization ability to profile diverse activities. To address it, this paper proposes IoTEnsemble, an ensemble network anomaly detection framework. We propose a tree-based activity clustering method that aggregates network flows dedicated to the same activity so that their traffic patterns remain identical. Based on the clustering result, we implement an ensemble model in which each submodel only needs to profile a specific activity, which highly reduces the burden of a single model’s generalization ability. For evaluation, we build a 57.1 GB IoT dataset collected in 9 months composed of comprehensive normal and malicious traffic. Our evaluation proves that IoTEnsemble possesses a state-of-the-art detection performance on various IoT botnet malware and attack traffic, exhibiting a significantly better result than other baselines in a more intelligent and functional IoT network.

源语言英语
主期刊名Computer Security – ESORICS 2022 - 27th European Symposium on Research in Computer Security, Proceedings
编辑Vijayalakshmi Atluri, Roberto Di Pietro, Christian D. Jensen, Weizhi Meng
出版商Springer Science and Business Media Deutschland GmbH
569-588
页数20
ISBN(印刷版)9783031171451
DOI
出版状态已出版 - 2022
活动27th European Symposium on Research in Computer Security, ESORICS 2022 - Hybrid, Copenhagen, 丹麦
期限: 26 9月 202230 9月 2022

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
13555 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议27th European Symposium on Research in Computer Security, ESORICS 2022
国家/地区丹麦
Hybrid, Copenhagen
时期26/09/2230/09/22

指纹

探究 'IoTEnsemble: Detection of Botnet Attacks on Internet of Things' 的科研主题。它们共同构成独一无二的指纹。

引用此