<p>Smart interconnected devices belonging to the Internet of Things ecosystem are resource-constrained in terms of hardware and software. They are also prime attack targets for malicious parties. Although there has been an extensive exploration of attack detection methods rooted in machine learning, such approaches necessitate high processing overhead, which is ill-suited for devices of modest processing capabilities. Furthermore, machine learning algorithms are opaque black boxes. Therefore, we present a novel hybrid approach to detect distributed denial-of-service attacks using fuzzy cognitive maps paired with machine learning feature selection. Our approach incorporates contextual information (features) drawn from network packets. We utilize feature selection methods to compute the weights of the features. The weights capture the influence of each input feature on the target output feature that determines the classification of any packet as malicious or benign. The features and weights are used to construct a fuzzy cognitive map for each type of attack. The fuzzy cognitive map is then used to train and test the dataset. We also auto-compute a threshold value that allows our model to classify a packet as malicious or benign. Our model performs best using the weights computed by two particular statistical feature selection algorithms, namely, SelectKBest-Classification and SelectKBest Chi-squared, combined with FCM. Our experiments show that this hybrid approach is simple, reliable, and transparent with a low memory footprint, and therefore well-suited for devices with limited resources.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An FCM-based hybrid method for DDoS attack detection in resource-constrained devices

  • Prathibha Keshavamurthy,
  • Sarvesh Kulkarni

摘要

Smart interconnected devices belonging to the Internet of Things ecosystem are resource-constrained in terms of hardware and software. They are also prime attack targets for malicious parties. Although there has been an extensive exploration of attack detection methods rooted in machine learning, such approaches necessitate high processing overhead, which is ill-suited for devices of modest processing capabilities. Furthermore, machine learning algorithms are opaque black boxes. Therefore, we present a novel hybrid approach to detect distributed denial-of-service attacks using fuzzy cognitive maps paired with machine learning feature selection. Our approach incorporates contextual information (features) drawn from network packets. We utilize feature selection methods to compute the weights of the features. The weights capture the influence of each input feature on the target output feature that determines the classification of any packet as malicious or benign. The features and weights are used to construct a fuzzy cognitive map for each type of attack. The fuzzy cognitive map is then used to train and test the dataset. We also auto-compute a threshold value that allows our model to classify a packet as malicious or benign. Our model performs best using the weights computed by two particular statistical feature selection algorithms, namely, SelectKBest-Classification and SelectKBest Chi-squared, combined with FCM. Our experiments show that this hybrid approach is simple, reliable, and transparent with a low memory footprint, and therefore well-suited for devices with limited resources.