Adversarial RL-Based IDS for Evolving Data Environment in 6LoWPAN

Adversarial RL-Based IDS for Evolving Data Environment in 6LoWPAN
复制标题

DOI:
10.1109/tifs.2022.3214099
复制
发表时间:
2022
影响因子:
6.8
通讯作者:
A. Pasikhani;John A. Clark;P. Gope
A. Pasikhani;John A. Clark;P. Gope
中科院分区:
计算机科学1区
文献类型:
--
作者:
A. Pasikhani;John A. Clark;P. Gope

文献摘要

相似文献

低功耗和有损网络(LLN)由计算能力、内存和能量资源受限的节点组成。LLN节点支持众多设备(例如,温度、湿度和浊度传感器,以及电机、阀门和其他执行器)之间的无处不在的连接,以感知、控制和存储其环境的属性。他们经常被部署在敌对、无人看管和不利的条件下。确保它们的安全往往变得非常具有挑战性。互连的LLN设备的范围构成了一系列的路由威胁(例如,虫洞、灰洞、DIO抑制和增加秩攻击)。因此,一个高效有效的入侵检测系统(入侵检测系统)对于识别低功率无线个人网(6LoWPAN)上的IPv6异常活动至关重要。本文提出了一个健壮的对抗性强化学习(ARL)框架来为不断变化的数据环境生成高效的入侵检测系统。ARL和增量式机器学习的集成有助于生成资源高效和健壮的入侵检测检测器。我们特别演示了这种方法如何利用“概念漂移”检测和适应的概念来处理环境中不可避免的变化,从而使入侵检测系统有最好的机会检测到当前配置文件中的攻击。所考虑的路由攻击范围是迄今为止最全面的。首次区分和解决了旨在破坏6LoWPAN的基于黑盒和灰盒ML的对手。
Low-power and Lossy Networks (LLNs) comprise nodes characterised by constrained computational power, memory, and energy resources. The LLN nodes empower ubiquitous connections amongst numerous devices (e.g. temperature, humidity, and turbidity sensors, together with motors, valves and other actuators) to sense, control and store properties of their environments. They are often deployed in hostile, unattended, and unfavourable conditions. Securing them often becomes very challenging. The extent of interconnected LLN devices poses a series of routing threats (e.g. wormhole, grayhole, DIO suppression, and increase rank attacks). Consequently, an efficient and effective intrusion detection system (IDS) is of utmost importance in identifying anomalous activities in the IPv6 over Low-powered Wireless Personal Area Networks (6LoWPAN). This article proposes a robust Adversarial Reinforcement Learning (ARL) framework to generate efficient IDSs for evolving data environments. The integration of ARL and incremental machine-learning facilitates the generation of resource-efficient and robust IDS detectors. We demonstrate in particular how such an approach, leveraging notions of ‘concept drift’ detection and adaptation, can handle inevitable changes in the environment, giving the IDS best chances of detecting attacks in the current profile. The range of routing attacks considered is the most comprehensive to date. For the first time, Black-box and Grey-box ML-based adversaries aiming to destabilise the 6LoWPAN are distinguished and addressed.