Enhancing IoT Botnet Attack Detection in SOCs with an Explainable Active Learning Framework

Rajesh Kalakoti, Sven Nõmm, Hayretdin Bahşi · 2024

The widespread use of Internet of Things (IoT) devices has raised the threat of botnet attacks, presenting significant challenges for security operations centres (SOCs). While machine learning techniques have shown promising results in detecting these attacks, their effectiveness is often limited by the lack of labeled data and the need for greater transparency in the decision-making process of labeling. We propose an explainable active learning framework incorporating post-hoc explainability methods, such as LIME and SHAP, into the active learning process for detecting IoT botnet attacks in a multi-class classification setting. Our framework enables SOC analysts to provide informed annotations, while the explainability methods offer insights into the model’s decision-making process. We employ uncertainty sampling and query-by-committee strategies to select the most informative instances for labeling, and we evaluate the quality of the explanations using various quantitative metrics. Experimental results demonstrate that our explainable active learning framework achieves high detection performance while enhancing the trust and transparency between the SOC analysts and the learning model.

Read the paper · More papers on PaperTik