From Data to Defense: Real-Time Detection of Botnets in IoT Using LSTM Networks
Shadi Sadeghpour, Farhath Zareen, William A. Johnson · 2024
As the Internet of Things (IoT) continues to expand, integrating countless new devices and technologies, the associated attack surface widens accordingly. In an era where the IoT market is increasingly driven by profit, with security often relegated to an afterthought, traditional defense mechanisms fall short in detecting both known and novel attacks with high accuracy. To address these challenges, this work explores the application of time series analysis of the popular Bot-IoT dataset. We present a data preprocessing method that allows sequential networks to make real-time decisions based on information that would be available to a device in a real IoT network. To this end, we introduce a new feature, Time Difference, which measure the difference in time between messages sent between the same source and destination. To evaluate our data preprocessing steps, we train a simple LSTM network, and achieve an overall accuracy of 97%. Finally, we extract the 10 best features from our LSTM network for future researchers to use in more advanced time series analysis of Intrusion Detection System (IDS) datasets. Our results indicate that our proposed time series analysis outperforms existing multiclass methodologies.