Detection of DoS attacks exploiting SUBSCRIBE messages of the MQTT protocol

Dmitrii I. Dikii, Aleksey Tikhomirov · International Journal of Computers and Applications · 2020

In this paper, the authors consider DoS attacks implemented in Internet of Things networks employed on ‘publisher-subscriber’ structure. The objects of the research are the SUBSCRIBE messages of the MQTT Protocol. The modeling of anomalous IoT devices’ behavior caused by frequent sending of this type of messages showed that there is a significant increase of data time processing on the gateway and it can lead to network failure. The detection of devices’ anomalous behavior is based on the proposed feature vector and considered classifiers: Artificial neural network (multilayer perceptron), Random forest algorithm, Support vector machine. The obtained results of the effectiveness for approaches of different classifiers were compared. The comparison demonstrated that the messages sending frequency from a legitimate device used in training of the classifiers greatly influence the quality of detection.

Read the paper · More papers on PaperTik