An Ensemble of Deep Recurrent Neural Networks for Detecting IoT Cyber Attacks Using Network Traffic

An Ensemble of Deep Recurrent Neural Networks for Detecting IoT Cyber Attacks Using Network Traffic
复制标题

DOI:
10.1109/jiot.2020.2996425
复制
发表时间:
2020-05
影响因子:
10.6
通讯作者:
Mahdis Saharkhizan;Amin Azmoodeh;A. Dehghantanha;K. Choo;R. Parizi
Mahdis Saharkhizan;Amin Azmoodeh;A. Dehghantanha;K. Choo;R. Parizi
中科院分区:
计算机科学1区
文献类型:
--
作者:
Mahdis Saharkhizan;Amin Azmoodeh;A. Dehghantanha;K. Choo;R. Parizi

文献摘要

被引文献

相似文献

物联网(IoT)设备和系统将越来越多地成为网络犯罪分子(包括民族国家赞助或附属的威胁行为者)的目标,因为它们成为我们互联社会和生态系统不可或缺的一部分。然而,由于部署的规模和多样性、快节奏的网络威胁环境以及许多其他因素,这些设备和系统的安全面临着挑战。因此,在本文中,我们设计了一种使用高级深度学习来检测针对物联网系统的网络攻击的方法。具体来说,我们的方法将一组长短期记忆(LSTM)模块集成到一组检测器中。然后使用决策树合并这些模块,以在最后阶段获得聚合输出。我们使用Modbus网络流量的真实数据集评估了我们方法的有效性,并在检测针对物联网设备的网络攻击时获得了超过99%的准确率。
Internet-of-Things (IoT) devices and systems will be increasingly targeted by cybercriminals (including nation state-sponsored or affiliated threat actors) as they become an integral part of our connected society and ecosystem. However, the challenges in securing these devices and systems are compounded by the scale and diversity of deployment, the fast-paced cyber threat landscape, and many other factors. Thus, in this article, we design an approach using advanced deep learning to detect cyber attacks against IoT systems. Specifically, our approach integrates a set of long short-term memory (LSTM) modules into an ensemble of detectors. These modules are then merged using a decision tree to arrive at an aggregated output at the final stage. We evaluate the effectiveness of our approach using a real-world data set of Modbus network traffic and obtain an accuracy rate of over 99% in the detection of cyber attacks against IoT devices.