MQTT has become a standard for communication in Internet-of-Things (IoT) applications, facilitating the exchange of sensor data and commands in cyber-physical systems (CPS). However, its use of TCP makes it vulnerable to attacks, compromising IoT security. This paper addresses CPS dependability, focusing on IoT subsystem security (CPS-IoT). We propose a novel CPS-IoT traffic surveillance model for effective intrusion detection. This model includes: i) a process for generating realistic attack datasets, simulating Hping and Loic attacks on MQTT-aware IoT networks, and ii) the development of intrusion detection algorithms tailored for MQTT-aware networks under TCP-based attacks. Two intrusion detection classifiers are introduced and compared: a lightweight heuristic (LH) classifier and a machine learning (ML) classifier. The LH classifier, while comparable in accuracy to the ML classifier, has a higher rate of false negatives. The paper explores deploying these classifiers separately or as a hybrid model, where traffic is first classified by the LH classifier and then re-evaluated by the ML classifier, reducing false negatives. The experimental results and performance evaluation showcase the efficiency of the proposed intrusion detection algorithms, emphasizing the need for strong security measures in IoT deployments. By providing valuable insights into CPS-IoT security, this paper contributes to the broader understanding of ensuring the dependability and resilience of IoT ecosystems against potential cyber threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cyber Physical Systems Dependability Using CPS-IoT Traffic Surveillance

  • Landry Mbale,
  • Antoine Bagula

摘要

MQTT has become a standard for communication in Internet-of-Things (IoT) applications, facilitating the exchange of sensor data and commands in cyber-physical systems (CPS). However, its use of TCP makes it vulnerable to attacks, compromising IoT security. This paper addresses CPS dependability, focusing on IoT subsystem security (CPS-IoT). We propose a novel CPS-IoT traffic surveillance model for effective intrusion detection. This model includes: i) a process for generating realistic attack datasets, simulating Hping and Loic attacks on MQTT-aware IoT networks, and ii) the development of intrusion detection algorithms tailored for MQTT-aware networks under TCP-based attacks. Two intrusion detection classifiers are introduced and compared: a lightweight heuristic (LH) classifier and a machine learning (ML) classifier. The LH classifier, while comparable in accuracy to the ML classifier, has a higher rate of false negatives. The paper explores deploying these classifiers separately or as a hybrid model, where traffic is first classified by the LH classifier and then re-evaluated by the ML classifier, reducing false negatives. The experimental results and performance evaluation showcase the efficiency of the proposed intrusion detection algorithms, emphasizing the need for strong security measures in IoT deployments. By providing valuable insights into CPS-IoT security, this paper contributes to the broader understanding of ensuring the dependability and resilience of IoT ecosystems against potential cyber threats.