Back to Search
Start Over
ADEPT: Detection and Identification of Correlated Attack Stages in IoT Networks
- Source :
- IEEE Internet of Things Journal. 8:6591-6607
- Publication Year :
- 2021
- Publisher :
- Institute of Electrical and Electronics Engineers (IEEE), 2021.
-
Abstract
- The fast-growing Internet-of-Things (IoT) market has opened up a large threat landscape, given the wide deployment of IoT devices in both consumer and commercial spaces. Attacks on IoT devices generally consist of multiple stages and are dispersed spatially and temporally. These characteristics make it challenging to detect and identify the attack stages using solutions that tend to be localized in space and time. In this work, we present Adept , a distributed framework to detect and identify the individual attack stages in a coordinated attack. Adept works in three phases. First, network traffic of IoT devices is processed locally for detecting anomalies with respect to their benign profiles. Any alert corresponding to a potential anomaly is sent to a security manager, where aggregated alerts are mined, using frequent itemset mining (FIM), for detecting patterns correlated across both time and space. Finally, using both alert-level and pattern-level information as features, we employ a machine learning approach to identify individual attack stages in the generated alerts. We carry out extensive experiments, with emulated and realistic network traffic; the results demonstrate the effectiveness of the proposed framework in terms of its ability in attack-stage detection and identification.
- Subjects :
- Computer Networks and Communications
Computer science
business.industry
020206 networking & telecommunications
Denial-of-service attack
Adept
02 engineering and technology
computer.software_genre
Computer Science Applications
Identification (information)
Hardware and Architecture
Software deployment
Signal Processing
0202 electrical engineering, electronic engineering, information engineering
Task analysis
Malware
020201 artificial intelligence & image processing
Security management
Data mining
Internet of Things
business
computer
Information Systems
Subjects
Details
- ISSN :
- 23722541
- Volume :
- 8
- Database :
- OpenAIRE
- Journal :
- IEEE Internet of Things Journal
- Accession number :
- edsair.doi...........196b4dc91d18d93dd9801006b1b1b1bd