N-BaIoT-Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders

N-BaIoT-Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders
复制标题

DOI:
10.1109/mprv.2018.03367731
复制
发表时间:
2018-07-01
影响因子:
1.6
通讯作者:
Elovici, Yuval
Elovici, Yuval
中科院分区:
计算机科学4区
文献类型:
--
作者:
Meidan, Yair;Bohadana, Michael;Elovici, Yuval

文献摘要

被引文献

相似文献

比台式计算机更容易受到攻击的物联网设备的激增导致基于物联网的僵尸网络攻击增加。为了减轻这种威胁,需要新的方法来检测从受感染的物联网设备发起的攻击,并区分长达数小时和毫秒的基于物联网的攻击。在本文中,我们提出了一种新颖的基于网络的物联网异常检测方法,称为 N-BaIoT,该方法提取网络的行为快照,并使用深度自动编码器来检测来自受感染物联网设备的异常网络流量。为了评估我们的方法,我们使用两个众所周知的基于物联网的僵尸网络 Mirai 和 BASHLITE 感染了实验室中的九台商业物联网设备。评估结果表明,我们提出的方法能够准确、即时地检测从属于僵尸网络的受感染物联网设备发起的攻击。
The proliferation of IoT devices that can be more easily compromised than desktop computers has led to an increase in IoT-based botnet attacks. To mitigate this threat, there is a need for new methods that detect attacks launched from compromised IoT devices and that differentiate between hours-and milliseconds-long IoT-based attacks. In this article, we propose a novel network-based anomaly detection method for the IoT called N-BaIoT that extracts behavior snapshots of the network and uses deep autoencoders to detect anomalous network traffic from compromised IoT devices. To evaluate our method, we infected nine commercial IoT devices in our lab with two widely known IoT-based botnets, Mirai and BASHLITE. The evaluation results demonstrated our proposed method's ability to accurately and instantly detect the attacks as they were being launched from the compromised IoT devices that were part of a botnet.