Detecting Network Traffic Intrusions on Memory Constrained Embedded Systems
Shiyu Su, Ebelechukwu Nwafor · 2021
In recent years, there has been an increase in the number of internet connected devices also known as the Internet of Things (IoT). Traditional machine learning (ML) algorithms have proven to be useful tools for intrusion detection on both computing and memory-constrained embedded systems. ML approaches can also prove to be beneficial in the detection of advanced persistent threats in an IoT environment. However, incorporating intensive ML algorithms into the IoT ecosystem can be challenging since most of these IoT devices operate on strict memory and computing requirements. In this paper, we analyze and compare the effectiveness of several widely used machine learning algorithms–such as Random Forest, Support Vector Machine (SVM), and K-Nearest Neighbor (K-NN)–in detecting malicious intrusion in an IoT ecosystem. We evaluate our approach using an open source intrusion detection dataset which consists of a wide variety of IoT botnet attacks. In addition, we evaluate our models on memory-restricted virtual machines to simulate Internet of Things (IoT) devices, and test the execution time using the constrained memory. The results show that each approach is able to detect malicious network traffic with high accuracy.