Edge-Assisted IoT Intrusion Detection Using Leakage-Aware Learning, Rare-Attack
Robustness, and Explainable Model Analysis

Abstract

IoT networks produce high amounts of heterogeneous traffic and are exceptionally vulnerable to malicious activ- ity, and most deployment environments demand fast and lightweight security decision-making at the edge. By out- lining an edge-assisted IoT anomaly detection model, this paper will be based on the TON IoT network data set and test both predictive and operational aspects. The proposed methodology is a combination of leakage-aware data clean- ing, dual features representations of various model families, comparative analysis of classical machine learning, deep ma- chine learning and anomaly-based models, stress testing of rare attacks, classification of different attack types, explain- ability analysis, repeated-seed robustness analysis, feature ablation, and deployment-based ranking. The last dataset was cleaned and leakage mitigated, with 190,474 samples and 23 predictive features. LightGBM and XGBoost were the most overall high-performing binary anomaly detectors, with both having an F1-score of 0.999108, and LightGBM having a ROC-AUC of 0.999984. In the case of rare-attack, XGBoost was the most powerful model with the 1 percent attack ratio with an F1-score of 0.831683. In the case of mul- ticlass attacks-type classification, XGBoost had the highest accuracy and macro F1 of 0.988765 and 0.965683 respec- tively, compared to other models evaluated. The findings also reveal that a high level of detection can be maintained at lower feature settings, whereas edge-based analysis could point to Decision Tree as the most efficient deployment-wise model due to low latency and minimal memory footprint. In general, the results indicate that the suggested frame- work offers effective, interpretable, and robust, as well as edge-efficient IoT intrusion detection.

Citation details of the article



Journal: International Journal of Applied Mathematics
Journal ISSN (Print): ISSN 1311-1728
Journal ISSN (Electronic): ISSN 1314-8060
Volume: 35
Issue: 6
Year: 2022

Download Section



Download the full text of article from here.

You will need Adobe Acrobat reader. For more information and free download of the reader, please follow this link.

References

  1. [1] E. Gyamfi and A. Jurcut, “Intrusion detection in internet of things systems: a review on design approaches leveraging multi-access edge computing, machine learning, and datasets,” Sensors, vol. 22, no. 10, p. 3744, 2022.
  2. [2] T. M. Booij, I. Chiscop, E. Meeuwissen, N. Moustafa, and F. T. Den Hartog, “Ton iot: The role of heterogeneity and the need for standardization of features and attack types in iot network intrusion data sets,” IEEE Internet of Things Journal, vol. 9, no. 1, pp. 485–496, 2021.
  3. [3] X. Yu, X. Yang, Q. Tan, C. Shan, and Z. Lv, “An edge computing based anomaly detection method in iot industrial sustainability,” Applied Soft Computing, vol. 128, p. 109486, 2022.
  4. [4] Y. Meidan, M. Bohadana, Y. Mathov, Y. Mirsky, A. Shabtai, D. Breitenbacher, and Y. Elovici, “N-baiot—network-based detection of iot botnet attacks using deep autoencoders,” IEEE Pervasive Computing, vol. 17, no. 3, pp. 12–22, 2018.
  5. [5] A. A. Diro and N. Chilamkurti, “Distributed attack detection scheme using deep learning approach for internet of things,” Future Generation Computer Systems, vol. 82, pp. 761–768, 2018.
  6. [6] R. Doshi, N. Apthorpe, and N. Feamster, “Machine learning ddos detection for consumer internet of things devices,” in 2018 IEEE security and privacy workshops (SPW). IEEE, 2018, pp. 29–35.
  7. [7] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset,” Future Generation Computer Systems, vol. 100, pp. 779–796, 2019.
  8. [8] N. Moustafa, “New generations of internet of things datasets for cybersecurity applications based machine learning: Ton iot datasets,” in Proceedings of the eResearch Australasia Conference, Brisbane, Australia, 2019, pp. 21–25.
  9. [9] A. Alsaedi, N. Moustafa, Z. Tari, A. Mahmood, and A. Anwar, “Ton iot telemetry dataset: A new generation dataset of iot and iiot for data-driven intrusion detection systems,” Ieee Access, vol. 8, pp. 165 130–165 150, 2020.
  10. [10] N. Moustafa, M. Keshky, E. Debiez, and H. Janicke, “Federated ton iot windows datasets for evaluating ai-based security applications,” in 2020 IEEE 19th international conference on trust, security and privacy in computing and communications (TrustCom). IEEE, 2020, pp. 848–855.
  11. [11] N. Moustafa, M. Ahmed, and S. Ahmed, “Data analyticsenabled intrusion detection: Evaluations of ton iot linux datasets,” in 2020 IEEE 19th international conference on trust, security and privacy in computing and communications (TrustCom). IEEE, 2020, pp. 727–735.
  12. [12] M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study,” Journal of Information Security and Applications, vol. 50, p. 102419, 2020.
  13. [13] H. Hindy, E. Bayne, M. Bures, R. Atkinson, C. Tachtatzis, and X. Bellekens, “Machine learning based iot intrusion detection system: An mqtt case study (mqtt-iot-ids2020 dataset),” in International networking conference. Springer, 2020, pp. 73–84.
  14. [14] P. Nimbalkar and D. Kshirsagar, “Feature selection for intrusion detection system in internet-of-things (iot),” ICT Express, vol. 7, no. 2, pp. 177–181, 2021.
  15. [15] M. A. Ferrag, O. Friha, L. Maglaras, H. Janicke, and L. Shu, “Federated deep learning for cyber security in the internet of things: Concepts, applications, and experimental analysis,” IEEe Access, vol. 9, pp. 138 509–138 542, 2021.
  16. [16] T. D. Nguyen, P. Rieger, M. Miettinen, A.-R. Sadeghi et al., “Poisoning attacks on federated learning-based iot intrusion detection system,” in Proc. workshop decentralized IoT syst. secur.(DISS), vol. 79, 2020, pp. 1–7.
  17. [17] E. ¨Ozer, M. Iskefiyeli, and J. Azimjonov, “Toward lightweight intrusion detection systems using the optimal and efficient feature pairs of the bot-iot 2018 dataset,” International Journal of Distributed Sensor Networks, vol. 17, no. 10, p. 15501477211052202, 2021.
  18. [18] W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Port mann, “E-graphsage: A graph neural network based intrusion detection system for iot,” in NOMS 2022-2022 IEEE/iFIP network operations and management symposium. IEEE, 2022, pp. 1–9.
  19. [19] S. Arisdakessian, O. A. Wahab, A. Mourad, H. Otrok, and M. Guizani, “A survey on iot intrusion detection: Federated learning, game theory, social psychology, and explainable ai as future directions,” IEEE Internet of Things Journal, vol. 10, no. 5, pp. 4059–4092, 2022.
  20. [20] P. Spadaccino and F. Cuomo, “Intrusion detection systems for iot: opportunities and challenges offered by edge computing and machine learning,” arXiv preprint arXiv:2012.01174, 2020.
  21. [21] S. Tsimenidis, T. Lagkas, and K. Rantos, “Deep learning in iot intrusion detection,” Journal of network and systems management, vol. 30, no. 1, p. 8, 2022.
  22. [22] B. I. Farhan and A. D. Jasim, “Survey of intrusion detection using deep learning in the internetof things,” Iraqi Journal For Computer Science and Mathematics, vol. 3, no. 1, p. 9, 2022.
  23. [23] S. Baniasadi, O. Rostami, D. Mart´ın, and M. Kaveh, “A novel deep supervised learning-based approach for intrusion detection in iot systems,” Sensors, vol. 22, no. 12, p. 4459, 2022.
  24. [24] O. A. Alzubi, J. A. Alzubi, M. Alazab, A. Alrabea, A. Awajan, and I. Qiqieh, “Optimized machine learning-based intrusion detection system for fog and edge computing environment,” Electronics, vol. 11, no. 19, p. 3007, 2022.
  25. [25] M. M. Alani and A. Miri, “Towards an explainable universal feature set for iot intrusion detection,” Sensors, vol. 22, no. 15, p. 5690, 2022.
  26. [26] A. Khudhu and K. Samsudin, “Iot intrusion detection using autoencoder and machine learning techniques,” J. Comp. Sci, vol. 18, no. 10, pp. 904–912, 2022.
  27. [27] H. Bangui and B. Buhnova, “Lightweight intrusion detection for edge computing networks using deep forest and bio-inspired algorithms,” Computers and Electrical Engineering, vol. 100, p. 107901, 2022.
  28. [28] I. Tareq, B. M. Elbagoury, S. El-Regaily, and E.-S. M. El-Horbaty, “Analysis of ton-iot, unw-nb15, and edge-iiot datasets using dl in cybersecurity for iot,” Applied Sciences, vol. 12, no. 19, p. 9572, 2022.
  29. [29] S. Neupane, J. Ables, W. Anderson, S. Mittal, S. Rahimi, I. Banicescu, and M. Seale, “Explainable intrusion detection systems (x-ids): A survey of current methods, challenges, and opportunities,” IEEE Access, vol. 10, pp. 112 392–112 415, 2022.
  30. [30] V. Chang, L. Golightly, P. Modesti, Q. A. Xu, L. M. T. Doan, K. Hall, S. Boddu, and A. Kobusi´nska, “A survey on intrusion detection systems for fog and cloud computing,” Future Internet, vol. 14, no. 3, p. 89, 2022.
  31. [31] Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai, “Kitsune: an ensemble of autoencoders for online network intrusion detection,” arXiv preprint arXiv:1802.09089, 2018.