Identifying Malicious Nodes in Multihop IoT Networks Using Diversity and Unsupervised Learning

Identifying Malicious Nodes in Multihop IoT Networks Using Diversity and Unsupervised Learning
复制标题

使用多样性和无监督学习识别多跳物联网网络中的恶意节点

DOI:
--
复制
发表时间:
2018
期刊:
2018 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
D. Tipper
D. Tipper
中科院分区:
--
文献类型:
--
作者:
Xin Liu;Mai Abdelhakim;P. Krishnamurthy;D. Tipper

文献摘要

被引文献

相似文献

物联网(IoT)应用中引入的连接性增加,使此类系统容易受到严重的安全威胁。在本文中,我们考虑了物联网网络中最具挑战性的威胁之一,其中设备在从源转发到目的地时(恶意或无意地)操纵信息包中传输的数据。我们提出了利用网络多样性来检测和识别可疑网络元素的无监督学习。我们提出的方法可以识别可疑节点沿着多跳传输路径和可变的攻击水平下的网络。更具体地说,我们为每个网络元素制定了一个贡献度量,它被用作基于节点行为对节点进行聚类的特征。我们提出了两种检测方法,即硬检测和软检测。在前者中,节点被聚类为恶意或良性组;而在后者中,节点根据其可疑级别被聚类为三组,然后高度可疑的节点被丢弃,并为剩余的节点评估更准确的贡献特征。软检测在有足够的网络多样性的情况下具有更高的检测精度。仿真结果表明,在网络中恶意节点所占比例不同以及存在信道错误的情况下,所提出的方法均能达到较高的检测精度。
The increased connectivity introduced in Internet of Things (IoT) applications makes such systems vulnerable to serious security threats. In this paper, we consider one of the most challenging threats in IoT networks, where devices manipulate (maliciously or unintentionally) the data transmitted in infor-mation packets as they are being forwarded from the source to the destination. We propose unsupervised learning that exploits network diversity to detect and identify suspicious networked elements. Our proposed method can identify suspicious nodes along multihop transmission paths and under variable attack levels within the network. More specifically, we formulate a contribution metric for each networked element, which is used as a feature to cluster the nodes based on their behavior. We proposed two detection approaches, namely hard detection and soft detection. In the former, nodes are clustered into malicious or benign group; while in the latter, nodes are clustered into three groups based on their suspicious level, then highly suspicious nodes are discarded and more accurate contribution features are evaluated for the remaining nodes. Soft detection has higher detection accuracy provided that there is sufficient network diversity. Simulation results show that the proposed methods achieve high detection accuracy under different percentages of malicious nodes in the network and in the existence of channel errors.