Design and Analysis of an Integrated Rule-Based and Machine Learning System for DoS Attack Detection in Wireless Sensor Networks
Shalini Swami, Pushpa Singh, Sansar Singh Chauhan · 2024
Security and threat are the major issues in Wireless Sensor Network (WSN). In WSN there are different types of attacks; among them Denial-of Service (DoS) attacks are very crucial. This paper aims to propose an integrated Rule-based and Machine Learning (ML) based intrusion detection system (IDS) to identify traffic flow as “normal” or “attacks”, while avoiding the imbalance problem of WSN-DS data set. WSN-DS has various features to identify the traffic flow. To attain efficient and speedy identification, we select relevant features using Information Gain (IG) and Gini Index (GI) methods to identify significant features that are employed to construct rules. Incoming traffic flows are then matched against these rules; if pattern matches then flow is classified as “normal,.” otherwise detected as an “attack.”. Furthermore, ML models are subsequently deployed to identify specific DoS attack types, including “Blackhole.”, “Grayhole.”, “TDMA (Scheduling).”, and “Flooding.”. We have used decision trees (DT), support vector machine (SVM), Gaussian Naive Bayes (NB) and K-Nearest Neighbour (KNN) with WSN-DS dataset to analyze and compare model accuracy. Among all ML models, the DT exhibits the maximum efficiency of 99.43% in identifying various types of DoS attacks. The proposed integrated rule and ML based method offers both speed and effectiveness in detecting DoS attacks since it is applied after balancing the dataset.