Hybrid Deep Learning for Botnet Attack Detection on IoT Networks using CNN-GRU

Edward Billy Hadipuspito, Vera Suryani · 2024

The rapid growth of Internet of Things also introduces security risks and attacks particularly for commercial IoT devices, which are often targeted by cybercriminals. To address these security challenges, we propose a Convolutional Neural Network-Gated Recurrent Unit (CNN-GRU) hybrid deep learning model to detect anomalies in nine commercial IoT devices. This CNN-GRU model leverages the strengths of both CNN and GRU. CNNs are renowned for their ability to extract spatial features from data, making them ideal for identifying patterns in IoT device data. On the other hand, GRUs are excellent at capturing temporal characteristics, allowing them to understand the sequence and timing of data points. The model was trained and evaluated using the N-BaIoT dataset, a comprehensive collection of network traffic from nine different commercial IoT devices. It achieved exceptional Fl-score results on differentiating normal and Bashlite botnet attack traffic. However, for certain types of attacks, the model is challenged. We also compared the performance with the CNN-LSTM model, another popular deep learning approach. The comparison was based on accuracy and training times. The results revealed that CNN-GRU surpassed the performance of CNN-LSTM for most device models, achieving the highest accuracy of 85.04%. Notably, it also achieved lower training times on all devices, with the largest difference being 82.04 second. This research highlights the efficiency of hybrid deep learning models like CNN-GRU in enhancing the security of commercial IoT devices by effectively detecting anomalies.

Read the paper · More papers on PaperTik