IoT-KEEPER: Detecting Malicious IoT Network Activity Using Online Traffic Analysis at the Edge

IoT-KEEPER: Detecting Malicious IoT Network Activity Using Online Traffic Analysis at the Edge
复制标题

DOI:
10.1109/tnsm.2020.2966951
复制
发表时间:
2020-03-01
影响因子:
5.3
通讯作者:
Tarkoma, Sasu
Tarkoma, Sasu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Hafeez, Ibbad;Antikainen, Markku;Tarkoma, Sasu

文献摘要

被引文献

相似文献

众所周知,物联网设备甚至容易受到微不足道的攻击,并且很容易受到损害。此外,物联网设备的资源限制和异构性使得使用传统的端点和网络安全解决方案来保护物联网安装变得不切实际。为了解决这个问题,我们提出了IoT Keeper,这是一个轻量级的系统,可以保护IoT的通信。IoT Keeper使用我们提出的异常检测技术在边缘网关处执行流量分析。它使用模糊C均值聚类和模糊插值方案相结合,分析网络流量和检测恶意网络活动。一旦检测到恶意活动,IoT Keeper会自动对生成此活动的IoT设备实施网络访问限制,并防止其攻击其他设备或服务。我们使用从真实世界测试平台收集的综合数据集对IoT Keeper进行了评估,其中包含流行的IoT设备。使用这个数据集,我们提出的技术实现了高准确性(约0.98)和低误报率(约0.02)检测恶意网络活动。我们的评估还表明,IoT Keeper具有较低的资源占用,并且可以检测和缓解各种网络攻击,而无需明确的攻击签名或复杂的硬件。
IoT devices are notoriously vulnerable even to trivial attacks and can be easily compromised. In addition, resource constraints and heterogeneity of IoT devices make it impractical to secure IoT installations using traditional endpoint and network security solutions. To address this problem, we present IoT-Keeper, a lightweight system which secures the communication of IoT. IoT-Keeper uses our proposed anomaly detection technique to perform traffic analysis at edge gateways. It uses a combination of fuzzy C-means clustering and fuzzy interpolation scheme to analyze network traffic and detect malicious network activity. Once malicious activity is detected, IoT-Keeper automatically enforces network access restrictions against IoT device generating this activity, and prevents it from attacking other devices or services. We have evaluated IoT-Keeper using a comprehensive dataset, collected from a real-world testbed, containing popular IoT devices. Using this dataset, our proposed technique achieved high accuracy (approximate to 0.98) and low false positive rate (approximate to 0.02) for detecting malicious network activity. Our evaluation also shows that IoT-Keeper has low resource footprint, and it can detect and mitigate various network attacks-without requiring explicit attack signatures or sophisticated hardware.