Attack Detection and Forensics Using Honeypot in IoT Environment

Attack Detection and Forensics Using Honeypot in IoT Environment
复制标题

在物联网环境中使用蜜罐进行攻击检测和取证

DOI:
--
复制
发表时间:
2018
期刊:
International Conference on Distributed Computing and Internet Technology
影响因子:
--
通讯作者:
C. Hota
C. Hota
中科院分区:
--
文献类型:
--
作者:
R. Shrivastava;Bazila Bashir;C. Hota

文献摘要

被引文献

相似文献

物联网(IoT)是一组部署了传感器的微型设备。物联网使嵌入式设备自动化并通过互联网控制它们。物联网的无处不在的部署为下一代互联网引入了一个愿景,在下一代互联网中,用户、计算系统和拥有传感和驱动能力的日常物品以前所未有的便利性和经济效益进行合作。由于物联网设备的使用增加,物联网网络容易受到远程登录(如SSH和SSL)的各种安全攻击。本文重点介绍使用Cowrie蜜罐捕获对物联网设备的攻击。我们采用各种机器学习算法,即朴素贝叶斯,J48决策树,随机森林和支持向量机(SVM)来分类这些攻击。该研究将攻击分为各种类别,如恶意负载,SSH攻击,XOR DDoS,间谍,可疑和干净。特征选择采用子集评估和最佳优先搜索。一旦选择了特征,我们使用所提出的SVM模型,并使用随机森林,朴素贝叶斯,J48决策树等基线模型评估其性能。训练模型的适应度是根据各种指标进行评估的,如准确度、灵敏度、精度和F分数,其中准确度从67.7%到97.39%不等。这项工作展示了包含机器学习模块,通过分析表现出的行为来分类攻击。最后,我们讨论了我们的观察蜜罐取证的命令执行的攻击者执行恶意攻击。
The Internet of Things (IoT) is a collection of tiny devices deployed with sensors. IoT automates embedded devices and controls them over the Internet. Ubiquitous deployment of IoT introduces a vision for the next generation of the Internet where users, computing systems, and everyday objects possessing sensing and actuating capabilities cooperate with unprecedented convenience and economic benefits. Due to the increased usage of IoT devices, the IoT networks are vulnerable to various security attacks by remote login (like SSH and Telnet). This paper focuses on capturing the attacks on IoT devices using Cowrie honeypot. We employ various machine learning algorithms, namely, Naive Bayes, J48 decision tree, Random Forest and Support Vector Machine (SVM) to classify these attacks. This research classifies attacks into various categories such as malicious payload, SSH attack, XOR DDoS, Spying, Suspicious and clean. Feature selection is carried out using subset evaluation and best first search. Once features are selected, we use the proposed SVM model and evaluate its performance with baseline models like Random Forest, Naive Bayes, J48 decision tree. The trained model’s fitness is evaluated on the basis of various metrics such as accuracy, sensitivity, precision, and F-score, where accuracy varies from 67.7% to 97.39%. This work exhibits the inclusion of machine learning module to classify attacks by analyzing the exhibit behavior. In the end, we discuss our observations of honeypot forensics over the commands executed by the attacker to execute malicious attack.