Permission-level risk profiling and anomaly detection in IoT using machine learning
摘要
The proposed study introduces a robust computational framework meant towards leveraging behavioral analysis of permission usage integrated with sophisticated Machine Learning (ML) techniques. The novelty associated with the model is the generation of a synthetic permission access dataset and facilitating scalable simulation of scenarios of diverse attacks in the Internet of Things (IoT). The study model has been implemented considering 4 use-cases of potential adversaries, viz., spyware, data exfiltration, root exploits, and location tracking. The model leverages a Gradient Boosting Classifier for differentiating regular threats from malicious ones based on the activities of users on IoT devices. A risk profiling system has been integrated towards critical permission, where various forms of supervised and unsupervised learning models have also been tested. The simulated study outcome shows the proposed scheme to accomplish 20% increased accuracy performance with maximized scalability and computational efficiencies in contrast to other machine learning schemes.