Explainable AI-Based DDOS Attack Identification Method for IoT Networks

被引:20
|
作者
Kalutharage, Chathuranga Sampath [1 ]
Liu, Xiaodong [1 ]
Chrysoulas, Christos [1 ]
Pitropakis, Nikolaos [1 ]
Papadopoulos, Pavlos [1 ]
机构
[1] Edinburgh Napier Univ, Sch Comp Engn & Build Environm, Edinburgh EH10 5DT, Scotland
关键词
explainable AI; DDoS attack; IoT network; feature influence; anomaly detection; supervised learning; DEFENSE-MECHANISM; FRAMEWORK; INTERNET;
D O I
10.3390/computers12020032
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The modern digitized world is mainly dependent on online services. The availability of online systems continues to be seriously challenged by distributed denial of service (DDoS) attacks. The challenge in mitigating attacks is not limited to identifying DDoS attacks when they happen, but also identifying the streams of attacks. However, existing attack detection methods cannot accurately and efficiently detect DDoS attacks. To this end, we propose an explainable artificial intelligence (XAI)-based novel method to identify DDoS attacks. This method detects abnormal behaviours of network traffic flows by analysing the traffic at the network layer. Moreover, it chooses the most influential features for each anomalous instance with influence weight and then sets a threshold value for each feature. Hence, this DDoS attack detection method defines security policies based on each feature threshold value for application-layer-based, volumetric-based, and transport control protocol (TCP) state-exhaustion-based features. Since the proposed method is based on layer three traffic, it can identify DDoS attacks on both Internet of Things (IoT) and traditional networks. Extensive experiments were performed on the University of Sannio, Benevento Instrution Detection System (USB-IDS) dataset, which consists of different types of DDoS attacks to test the performance of the proposed solution. The results of the comparison show that the proposed method provides greater detection accuracy and attack certainty than the state-of-the-art methods.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] Editorial: AI-based Data Intelligent for IoT Computing
    Yuyu Yin
    Stelios Fuentes
    Mobile Networks and Applications, 2023, 28 : 346 - 347
  • [32] Research on DDoS Attack Detection Based on ELM in IoT Environment
    Li, Zhihui
    Wei, Lihong
    Li, Wei
    Wei, Lai
    Chen, Minshi
    Lv, Ming
    Zhi, Xulong
    Wang, Chenguang
    Gao, Nan
    PROCEEDINGS OF 2019 IEEE 10TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2019), 2019, : 144 - 148
  • [33] Dynamic multiphase DDoS attack identification and mitigation framework to secure SDN-based fog-empowered consumer IoT Networks
    Chaudhary, Pooja
    Singh, A. K.
    Gupta, B. B.
    COMPUTERS & ELECTRICAL ENGINEERING, 2025, 123
  • [34] Detection of Adversarial Attacks in AI-Based Intrusion Detection Systems Using Explainable AI
    Tcydenova, Erzhena
    Kim, Tae Woo
    Lee, Changhoon
    Park, Jong Hyuk
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2021, 11
  • [35] Build confidence and acceptance of AI-based decision support systems - Explainable and liable AI
    Nicodeme, Claire
    2020 13TH INTERNATIONAL CONFERENCE ON HUMAN SYSTEM INTERACTION (HSI), 2020, : 20 - 23
  • [36] Detection of Adversarial Attacks in AI-Based Intrusion Detection Systems Using Explainable AI
    Tcydenova, Erzhena
    Kim, Tae Woo
    Lee, Changhoon
    Park, Jong Hyuk
    Human-centric Computing and Information Sciences, 2021, 11
  • [37] DDoS Attack Identification and Defense using SDN based on Machine Learning Method
    Yang Lingfeng
    Zhao Hui
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 166 - 170
  • [38] Neural Networks for DDoS Attack Detection using an Enhanced Urban IoT Dataset
    Hekmati, Arvin
    Grippo, Eugenio
    Krishnamachari, Bhaskar
    2022 31ST INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2022), 2022,
  • [39] Optimized Ensemble Model with Genetic Algorithm for DDoS Attack Detection in IoT Networks
    Saiyed, Makhduma F.
    Al-Anbagi, Irfan
    2024 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS 2024, 2024, : 433 - 438
  • [40] DXN: Dynamic AI-Based Analysis and Optimisation of IoT Networks' Connectivity and Sensor Nodes' Performance
    Lami, Ihsan
    Abdulkhudhur, Alnoman
    SIGNALS, 2021, 2 (03): : 570 - 585