Attack Pattern Recognition in the Internet of Things using Complex Event Processing and Machine Learning

José Roldán-Gómez, Juan Boubeta-­Puig, Juan Manuel Castelo Gómez, Javier Carrillo-Mondéjar, José Luis Martínez · 2021 IEEE International Conference on Systems, Man, and Cybernetics (SMC) · 2021

The Internet of Things (IoT) paradigm demands adapting traditional cybersecurity solutions to address the inherent limitations of IoT environments, in particular their low computational power and limited amount of memory and bandwidth. The Complex Event Processing (CEP) technology has proven to be useful in this context by deploying a CEP engine for detecting real-time attacks in an IoT network. However, CEP is only capable of detecting attacks that have been previously modeled as event patterns. This requires a domain expert who knows the conditions that must be satisfied so that certain attacks can be detected, thus identifying unmodeled ones is not possible. This paper aims to address this problem by proposing a machine learning algorithm that allows for the automatic creation of CEP patterns based on categorized data if the goal is to classify attacks, or even uncategorized data if the objective is to detect anomalies. An evaluation of the effectiveness of the automatically generated patterns for recognizing different attacks in IoT environments is also conducted in this paper.

Read the paper · More papers on PaperTik