Improving DDoS Detection in IoT Networks Through Analysis of Network Traffic Characteristics
Wanderson L. Costa, Matheus M. Silveira, Thelmo Pontes de Araujo, Rafael L. Gomes · 2020
The evolution of devices allowed the evolution of service provision, applying new technologies based on the Internet of Things (IoT). Most of IoT devices have security vulnerabilities, making them susceptible to Distributed Denial of Service (DDoS) attacks. Thus, it is necessary to apply solutions that can detect it in IoT networks based on data about the network traffic. However, there is no standard of the most suitable traffic characteristics for DDoS detection, since the use of inappropriate characteristics harms the detection. Within this context, this paper presents an analysis of the most important traffic characteristics for detecting DDoS in IoT networks, in order to support a detection mechanism based on Machine Learning (ML). Experiments using a real dataset suggest that the proposed mechanism has an accuracy close to 99% when the most suitable characteristics are selected.