ADROIT: Detecting Spatio-Temporal Correlated Attack-Stages in IoT Networks
Dinil Mon Divakaran, Rhishi Pratap Singh, Kalupahana Liyanage Kushan Sudheera, Mohan Gurusamy, Vinay Sachidananda · 2020
As IoT devices become increasingly deployed for personal as well as commercial purposes, the cyber threat landscape is also changing with recent years witnessing attacks with higher intensity and sophistication.Attacks consists of multiple stages, such that the individual attack-stages not only happen at different times but are also dispersed spatially across large number of IoT devices residing in multiple networks.These characteristics make it challenging to detect the attackstages using solutions that are localized in space and time.This work looks into the problem of detection of attack-stages in IoT networks.We develop Adroit, a system that correlates anomalies across different networks and different time-windows, using a scalable network architecture.In Adroit, network traffic of devices is processed locally to detect potential anomalous behavior.Alerts on the anomalies are regularly sent to a security manager residing in the cloud, which employs a well-known data mining approach, FIM, to extract attack patterns.Results from our preliminary experiments conducted using an OpenStack environment are encouraging -Adroit is able to detect attackstages with high accuracy while filtering out much of false alerts.