AI Empowered Intrusion Detection for MQTT Networks

Steve Chesney, Kaushik Roy · 2022

This paper utilizes the MQTT IDS dataset to demonstrate how artificial intelligence (AI) algorithms can be used for intrusion detection. The MQTT dataset contains both benign and malicious IoT network traffic that includes both TCP and MQTT protocol-level information. The features within the MQTT IDS dataset are labeled for binary classification of cyberattacks, as various attack types were injected in the configured network to simulate real-world conditions. The dataset consists of Ave recorded scenarios - normal operations and four attack scenarios: (1) Aggressive scan (Scan A), (2) User Datagram Protocol (UDP) scan (Scan sU), (3) Sparta SSH brute-force (Sparta), and the (4) MQTT brute-force attack (MQTT BF). For this study, both traditional machine learning and deep learning techniques were used to classify attacks with a high level of accuracy. For traditional machine learning, the Random Forest, Logistic Regression, Decision Tree, K-Nearest Neighbors, and the Support Vector Machine algorithms were used. For deep learning, a Deep Neural Network (DNN) and a Convolutional Neural Network (CNN) were evaluatedt.

Read the paper · More papers on PaperTik