Hardening machine learning denial of service (DoS) defences against adversarial attacks in IoT smart home networks

被引:48
|
作者
Anthi, Eirini [1 ]
Williams, Lowri [1 ]
Laved, Amir [1 ]
Burnap, Pete [1 ]
机构
[1] Cardiff Univ, Sch Comp Sci Informat, Cardiff, Wales
基金
英国工程与自然科学研究理事会;
关键词
Internet of things (IoT); Smart homes; Networking; Supervised machine learning; Adversarial machine learning; Attack detection; Intrusion detection systems; INTERNET; THINGS;
D O I
10.1016/j.cose.2021.102352
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning based Intrusion Detection Systems (IDS) allow flexible and efficient automated detection of cyberattacks in Internet of Things (IoT) networks. However, this has also created an additional attack vector; the machine learning models which support the IDS's decisions may also be subject to cyberattacks known as Adversarial Machine Learning (AML). In the context of IoT, AML can be used to manipulate data and network traffic that traverse through such devices. These perturbations increase the confusion in the decision boundaries of the machine learning classifier, where malicious network packets are often miss-classified as being benign. Consequently, such errors are bypassed by machine learning based detectors, which increases the potential of significantly delaying attack detection and further consequences such as personal information leakage, damaged hardware, and financial loss. Given the impact that these attacks may have, this paper proposes a rule-based approach towards generating AML attack samples and explores how they can be used to target a range of supervised machine learning classifiers used for detecting Denial of Service attacks in an IoT smart home network. The analysis explores which DoS packet features to perturb and how such adversarial samples can support increasing the robustness of supervised models using adversarial training. The results demonstrated that the performance of all the top performing classifiers were affected, decreasing a maximum of 47.2 percentage points when adversarial samples were present. Their performances improved following adversarial training, demonstrating their robustness towards such attacks. Crown Copyright (c) 2021 Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Detection of Distributed Denial of Service Attacks using Machine Learning Algorithms in Software Defined Networks
    Meti, Nisharani
    Narayan, D. G.
    Baligar, V. P.
    2017 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2017, : 1366 - 1371
  • [32] A localized architecture for detecting denial of service (DoS) attacks in wireless ad hoc networks
    Denko, MK
    Intelligence in Communication Systems, 2005, 190 : 135 - 146
  • [33] Mitigation Services on SDN for Distributed Denial of Service and Denial of Service Attacks Using Machine Learning Techniques
    Ramprasath, J.
    Krishnaraj, N.
    Seethalakshmi, V.
    IETE JOURNAL OF RESEARCH, 2024, 70 (01) : 70 - 81
  • [34] Preventing Denial of Service Attacks in IoT Networks through Verifiable Delay Functions
    Attias, Vidal
    Vigneri, Luigi
    Dimitrov, Vassil
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [35] Recognition of Denial-of-Service Attacks in IoT Networks with Linear Complexity Model
    Lautert, Henrique Fell
    Pioli Junior, Laercio
    de Macedo, Douglas D. J.
    16TH IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING, UCC 2023, 2023,
  • [36] Detection of Real-Time Distributed Denial-of-Service (DDoS) Attacks on Internet of Things (IoT) Networks Using Machine Learning Algorithms
    Mahdi, Zaed
    Abdalhussien, Nada
    Mahmood, Naba
    Zaki, Rana
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (02): : 2139 - 2159
  • [37] Enhancing intrusion detection against denial of service and distributed denial of service attacks: Leveraging extended Berkeley packet filter and machine learning algorithms
    Anand, Nemalikanti
    Saifulla, M. A.
    Aakula, Pavan Kumar
    Ponnuru, Raveendra Babu
    Patan, Rizwan
    Reddy, Chegireddy Rama Prakasha
    IET COMMUNICATIONS, 2025, 19 (01)
  • [38] Adversarial Machine Learning Attacks on Multiclass Classification of IoT Network Traffic
    Pantelakis, Vasileios
    Bountakas, Panagiotis
    Farao, Aristeidis
    Xenakis, Christos
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [39] Distributed Denial of Service (DDoS) Attacks Detection: A Machine Learning Approach
    Samom, Premson Singh
    Taggu, Amar
    APPLIED SOFT COMPUTING AND COMMUNICATION NETWORKS, 2021, 187 : 75 - 87
  • [40] Detecting Distributed Denial of Service Attacks using Machine Learning Models
    Alghoson, Ebtihal Sameer
    Abbass, Onytra
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (12) : 616 - 622