An Adaptive Flow-based NIDS for Smart Home Networks Against Malware Behavior Using XGBoost combined with Rough Set Theory

Nasser Alsabilah, Danda B. Rawat · 2023

With the rapid proliferation of smart home devices, securing these networks from cyber threats is a vital concern. A common cyber intrusion in smart home networks is the compromise of IoT devices by malware to form botnets; furthermore, most proposed solutions lack domain adaptation, struggling to generalize to related distributions. Although deep learning has shown remarkable success in various domains, such as computer vision, natural language processing, and speech recognition as adaptive solutions. Nevertheless, it has its limitations in other domains, such as network security, because deep learning has the ability to work mainly with homogeneous unstructured datasets, in contrast to heterogeneous structured datasets. Despite efforts to address this with deep learning models for structured data (tabular data), gradient-boosted decision trees (GBDT) like XGBoost still outperform in this domain. However, recent empirical research indicated the significant impact of incorporating domain knowledge for training models that yield high F-1 scores on independent datasets compared to other models without incorporating domain knowledge. Therefore, this paper proposes a novel approach to develop an adaptive flow-based NIDS for smart home networks based on XGBoost combined with Rough Set Theory. The proposed approach is evaluated using the AUC-ROC Curve, Accuracy, and F1 score metrics, including assessment on independent data points. Experimental results highlight the effectiveness of our adaptive flow-based NIDS by combining XGBoost with acquired knowledge from Rough Set Theory.

Read the paper · More papers on PaperTik