Behavioral Novelty Detection for IoT Network Traffic

Salma Abdalla Hamad, Quan Z. Sheng, Wei Emma Zhang · 2024

IoT-applied solutions are changing the way the world perceives technology. IoT devices are now being used in a wide range of applications to transfer or share relevant information with each other, hence reducing human interventions. With such a wide spread of IoT solutions, security becomes a major concern. Many IoT devices are vulnerable due to several reasons including insecure implementations, poor life cycle management, and inappropriate configurations, leading to an increase in the risk of these devices getting exposed and attacked. However, the current security approaches for detecting compromised IoT devices are not efficient, especially for zero-day attacks as noted in Chapter 2 . Since no one knows what a new attack would look like, it will be useful to monitor and detect anomalies using accurate detection techniques. In Chapter 3 we discussed the effectiveness of ML algorithms identifying IoT devices within a network and we propose a security framework (BIN-IoT) that not only provides access control service but can continuously monitor the IoT devices’ communications to detect any drift from their normal behavior. This chapter develops a solution that acts as the anomaly detection module in our BIN-IoT security framework named Behavioral Novelty Detection for IoT Network Traffic (BND-IoT). BND-IoT probes the possibility of detecting IoT network traffic anomalies using novelty detection techniques, thus it can detect compromised IoT devices. BND-IoT trains a neural network with novel selected behavioral features extracted from benign traffic only and then uses the novelty techniques to detect any unusual traffic patterns. We show that the presented approach is effective in detecting anomalies within the network traffic of IoT devices with a strong average F1-score of 96.7%, and a low false rejection rate of 7%. The main content of this chapter has been published in Hamad et al. [ 105 ].

Read the paper · More papers on PaperTik