Hitting Moving Targets: Intelligent Prevention of IoT Intrusions on the Fly

被引:0
|
作者
Tan, Shuaishuai [1 ,2 ]
Liu, Wenyin [3 ]
Dong, Qingkuan [4 ]
Chan, Sammy [5 ]
Yu, Shui [6 ]
Zhong, Xiaoxiong [7 ]
He, Daojing [8 ]
机构
[1] Guangdong Univ Technol, Sch Comp Sci & Technol, Guangzhou 510006, Peoples R China
[2] Guangdong Prov Key Lab Novel Secur Intelligence Te, Shenzhen 518055, Peoples R China
[3] Zhongguancun Lab, Beijing 100094, Peoples R China
[4] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710071, Peoples R China
[5] City Univ Hong Kong, Dept Elect Engn, Hong Kong, Peoples R China
[6] Univ Technol Sydney, Sch Software, Sydney, NSW 2007, Australia
[7] Peng Cheng Lab, Dept New Networks, Shenzhen 518066, Peoples R China
[8] Harbin Inst Technol, Sch Comp Sci & Technol, Shenzhen, Peoples R China
关键词
Internet of Things; Feature extraction; Markov processes; IP networks; Prediction algorithms; Machine learning; Protocols; Internet of Things (IoT); machine learning (ML); network-level security and protection; traffic analysis; TRAFFIC CLASSIFICATION; NETWORK;
D O I
10.1109/JIOT.2023.3284155
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Massive Internet of Things (IoT) devices have been playing a critical role in both the cyber and physical worlds. Various cyber attacks pose significant risks to IoT. Machine learning-based intrusion detection system (IDS) has earned much research attention. However, the intrusion prevention system (IPS) is rarely explored. Realtime intrusion prevention is quite challenging because the decision has to be made during a flow rather than after it finishes. Restricted by aligning with the shortest flows, existing IPSs generally inspect only the very first packets, leading to information loss for accurate detection. In this article, we first measure the information loss quantitatively. Then we devise Sniper, an IoT IPS scheme consisting of a flow length predictor, a novel feature space, and an enhanced ensemble learning algorithm. The flow length predictor guides a proper prevention time point to preserve as much information as possible. The proposed Markov matrix-based feature encoding method further saves more information than existing ones. The enhanced learning algorithm ensures a low-false positive rate (FPR), which is critical for IPSs. We benchmark Sniper with one closed-world and three open-world data sets. The results show that Sniper achieves a 99.89% prevention rate and 0.03% FPR, which is superior to the five state-of-the-art baseline models.
引用
收藏
页码:21000 / 21012
页数:13
相关论文
共 44 条
  • [31] IoT-Based Intelligent Modeling of Smart Home Environment for Fire Prevention and Safety
    Saeed, Faisal
    Paul, Anand
    Rehman, Abdul
    Hong, Won Hwa
    Seo, Hyuncheol
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2018, 7 (01):
  • [32] Real-Time Threat Prevention System for Mitigating Intrusions by Dogs in Livestock Farming using IoT and Machine Learning
    Saeliw, Aekarat
    Hualkasin, Watcharasuda
    Puttinaovarat, Supattra
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2024, 13 (02): : 966 - 975
  • [33] Intelligent metasurface system for automatic tracking of moving targets and wireless communications based on computer vision
    Weihan Li
    Qian Ma
    Che Liu
    Yunfeng Zhang
    Xianning Wu
    Jiawei Wang
    Shizhao Gao
    Tianshuo Qiu
    Tonghao Liu
    Qiang Xiao
    Jiaxuan Wei
    Ting Ting Gu
    Zhize Zhou
    Fashuai Li
    Qiang Cheng
    Lianlin Li
    Wenxuan Tang
    Tie Jun Cui
    Nature Communications, 14
  • [34] Intelligent metasurface system for automatic tracking of moving targets and wireless communications based on computer vision
    Li, Weihan
    Ma, Qian
    Liu, Che
    Zhang, Yunfeng
    Wu, Xianning
    Wang, Jiawei
    Gao, Shizhao
    Qiu, Tianshuo
    Liu, Tonghao
    Xiao, Qiang
    Wei, Jiaxuan
    Gu, Ting Ting
    Zhou, Zhize
    Li, Fashuai
    Cheng, Qiang
    Li, Lianlin
    Tang, Wenxuan
    Cui, Tie Jun
    NATURE COMMUNICATIONS, 2023, 14 (01)
  • [35] Small tracking error correction for moving targets of intelligent electro-optical detection systems
    Shen, Cheng
    Wen, Zhijie
    Zhu, Wenliang
    Fan, Dapeng
    Ling, Mingyuan
    FRONTIERS OF MECHANICAL ENGINEERING, 2024, 19 (02)
  • [36] Randomized Moving Target Approach for MAC-Layer Spoofing Detection and Prevention in IoT Systems
    Madani, Pooria
    Vlajic, Natalija
    Maljevic, Ivo
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2022, 3 (04):
  • [37] Intelligent IDS: Venus Fly-Trap Optimization with Honeypot Approach for Intrusion Detection and Prevention
    Sai Chaithanya Movva
    Suresh Nikudiya
    Varsha S. Basanaik
    Damodar Reddy Edla
    Hanumanthu Bhukya
    Wireless Personal Communications, 2023, 128 : 1041 - 1063
  • [38] Intelligent IDS: Venus Fly-Trap Optimization with Honeypot Approach for Intrusion Detection and Prevention
    Movva, Sai Chaithanya
    Nikudiya, Suresh
    Basanaik, Varsha S.
    Edla, Damodar Reddy
    Bhukya, Hanumanthu
    WIRELESS PERSONAL COMMUNICATIONS, 2023, 128 (02) : 1041 - 1063
  • [39] A novel multi-scale intelligent recursive recognition method for three-dimensional moving targets
    Institute for Pattern Recognition and Artificial Intelligence, Huazhong University of Science and Technology, Wuhan 430074, China
    不详
    Zidonghua Xuebao, 2006, 5 (641-658):
  • [40] Hitting moving targets Continuous control of the acceleration of the hand on the basis of the target’s velocityContinuous control of the acceleration of the hand on the basis of the target’s velocity
    E. Brenner
    Jeroen B. J. Smeets
    Marc H. E. de Lussanet
    Experimental Brain Research, 1998, 122 : 467 - 474