KIND: A Novel Image-Mutual-Information-Based Decision Fusion Method for Saturation Attack Detection in SD-IoT

Man Xiao, Yunhe Cui, Qing Qian, Guowei Shen · IEEE Internet of Things Journal · 2022

Software-defined networking for IoT (SD-IoT), as an emerging architecture, is suffering from numerous security issues. Saturation attacks against the SDN switches and controllers are major security concerns in SD-IoT. When using the Dempster–Shafer evidence theory (DSE) to detect various saturation attacks, the simple mutual information calculation may cause information loss problem, leading to the decrease of detection accuracy. Therefore, how to avoid information loss problem to improve the detection performance is a key issue. Aiming to solve the above-mentioned issues, we propose KIND, a novel image mutual information-based decision fusion method for saturation attack detection in SD-IoT. The main idea of KIND is that it converts the probability matrix of binary classifiers to images and detects the saturation attacks by fusing these images. More specifically, when executing the evidence fusion, each evidence is converted to an image by a nonlinear transformation method. Each image is converted from the related probability-supported matrix. Then, the evidence can be fixed by comparing structural similarities among different images. After that, all evidence can be utilized to obtain the final detection results using the conducted combination rule. The evaluation results demonstrate that KIND can achieve high detection performance, which outperforms other state-of-the-art methods, in terms of TPR, TNR, FPR, FNR, accuracy, precision, recall, F-score, confusion matrix, ROC curves, PR curves, Chi-square test, correlation coefficient, and the quantitative strategy test. In conclusion, KIND can detect saturation attacks with high precision while causing acceptable storage overload.

Read the paper · More papers on PaperTik