PCIDS: Permission and Credibility-Based Intrusion Detection System in IoT Gateways

PCIDS: Permission and Credibility-Based Intrusion Detection System in IoT Gateways
复制标题

DOI:
10.1109/jiot.2023.3289206
复制
发表时间:
2024-01
影响因子:
10.6
通讯作者:
Chen Zhang;Zhuotao Lian;Huakun Huang;Chunhua Su
Chen Zhang;Zhuotao Lian;Huakun Huang;Chunhua Su
中科院分区:
计算机科学1区
文献类型:
--
作者:
Chen Zhang;Zhuotao Lian;Huakun Huang;Chunhua Su

文献摘要

相似文献

物联网(IoT)已经发展成为一个全球平台,通过智能服务极大地促进了人类生活。人们通过物联网访问智能设备是很简单的。然而,物联网设备的易访问性也给物联网带来了前所未有的安全挑战。为了确保物联网基础架构的安全,需要建立一个安全屏障,能够过滤对物联网设备的恶意访问,并实现入侵检测系统(IDS)与智能网关的集成。本文基于流量统计特征和身份认证建立了拒绝服务攻击、重放攻击、中间人攻击和漏洞攻击的威胁模型。它使用监督学习来获得可信度指标,以保护物联网系统。我们使用Django框架来验证身份授权信息,使用决策树来确定请求属性,并通过预先计算重要性比率(Ir),最大可信度指数$(P_{\martrm {max}})$和最小可信度指数$(P_{\martrm {min}})$,从物联网设备的实时状态反馈来对当前用户进行风险评估。通过管理员验证,我们进行收敛分析以获得用户属性。实验结果表明,我们的方法达到了94.7%的识别准确率。
The Internet of Things (IoT) has evolved into a global platform dramatically facilitating human life through intelligent services. It is straightforward for people to access smart devices through IoT. However, the easy accessibility of IoT devices has also led to unprecedented security challenges for the IoT. To ensure the security of the basic structure of IoT, we need to establish a security barrier that can filter malicious access to IoT devices and achieve the integration of intrusion detection systems (IDSs) with intelligent gateways. This article establishes threat models of Denial of Service, Replay, man-in-the-middle, and Loophole attacks based on statistical flow characteristics and identity authentication. It uses supervised learning to obtain the credibility index to protect the IoT system. We use the Django framework to verify identity authorization information, the decision tree to determine request attributes, and the real-time status feedback from IoT devices to perform a risk assessment on the current user by precalculating the importance ratio (Ir), the maximum credibility index $(P_{\mathrm {max}})$ , and the minimum credibility index $(P_{\mathrm {min}})$ . With administrator verification, we conduct a convergence analysis to obtain user attributes. The experimental results show that our approach achieves a recognition accuracy of 94.7%.