Detecting Behavioral Change of IoT Devices Using Clustering-Based Network Traffic Modeling

被引:44
|
作者
Sivanathan, Arunan [1 ]
Gharakheili, Hassan Habibi [1 ]
Sivaraman, Vijay [1 ]
机构
[1] Univ New South Wales, Sch Elect Engn & Telecommun, Sydney, NSW 2052, Australia
来源
IEEE INTERNET OF THINGS JOURNAL | 2020年 / 7卷 / 08期
关键词
Clustering; Internet-of-Things (IoT) devices; traffic modeling; SYSTEMS;
D O I
10.1109/JIOT.2020.2984030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is increasingly becoming a major challenge for network administrators to manage connected devices and sensors ranging from smart lights to smoke alarms and security cameras, at scale. IoT devices use an extensive variety of firmware and provide little (or no) access for the management of their operating systems and configurations. Operators of the IoT infrastructure, therefore, need to employ traffic classification models (trained by historical data) to automatically detect their assets on the network and ensure the health of devices against cyber attacks by monitoring their network behavior. On the other hand, IoT manufacturers often automatically perform firmware upgrades from cloud servers to devices that are operational in the field. This can potentially lead to a change of device behavior which makes it difficult for network operators to maintain classification models (incorporating changes without retraining the entire model). In this article, we develop a modular device classification architecture that allows operators to automatically detect IoT devices by their network activity and dynamically accommodate legitimate changes in assets (either addition of new device profile or upgrade of existing profiles). Our contributions are threefold: 1) we identify key traffic attributes that can be obtained from flow-level network telemetry to characterize the behavior of various IoT device types. We develop an unsupervised one-class clustering method for each device to detect their normal network behavior; 2) we tune device-specific clustering models and use them to classify IoT devices from their network traffic in real time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering; and 3) we evaluate the efficacy of our scheme by applying it to traffic traces (benign and attack) from ten real IoT devices and demonstrate its ability to detect behavioral changes with an overall accuracy of more than 94 %.
引用
收藏
页码:7295 / 7309
页数:15
相关论文
共 50 条
  • [31] IoT-KEEPER: Detecting Malicious IoT Network Activity Using Online Traffic Analysis at the Edge
    Hafeez, Ibbad
    Antikainen, Markku
    Ding, Aaron Yi
    Tarkoma, Sasu
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 45 - 59
  • [32] Recognizing the taste signals using the clustering-based fuzzy neural network
    Huang, YX
    Zhou, CG
    CHINESE JOURNAL OF ELECTRONICS, 2005, 14 (01): : 21 - 25
  • [33] Clustering-Based Interpretation of Deep ReLU Network
    Picchiotti, Nicola
    Gori, Marco
    AIXIA 2021 - ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, 13196 : 403 - 412
  • [34] Clustering-based selective neural network ensemble
    Fu Q.
    Hu S.-X.
    Zhao S.-Y.
    Journal of Zhejiang University-SCIENCE A, 2005, 6 (5): : 387 - 392
  • [35] Clustering-Based Network Inference with Submodular Maximization
    Kong, Lulu
    Gao, Chao
    Peng, Shuang
    PRICAI 2022: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I, 2022, 13629 : 118 - 131
  • [36] Clustering-Based Network Intrusion Detection System
    Fan, Chun-I
    Lai, Yen-Lin
    Shie, Cheng-Han
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [37] Identifying IoT Devices Based on Spatial and Temporal Features from Network Traffic
    Yin F.
    Yang L.
    Ma J.
    Zhou Y.
    Wang Y.
    Dai J.
    Security and Communication Networks, 2021, 2021
  • [38] IoT Devices Recognition Through Network Traffic Analysis
    Shahid, Mustafizur R.
    Blanc, Gregory
    Zhang, Zonghua
    Debar, Herve
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 5187 - 5192
  • [39] Network Traffic Characteristics of IoT Devices in Smart Homes
    Mainuddin, Md
    Duan, Zhenhai
    Dong, Yingfei
    30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [40] Sequential Behavioral Modeling for Scalable IoT Devices and Systems
    Korkan, Ege
    Kaebisch, Sebastian
    Kovatsch, Matthias
    Steinhorst, Sebastian
    PROCEEDINGS OF THE 2018 FORUM ON SPECIFICATION & DESIGN LANGUAGES (FDL), 2018,