Impact of Attack Variations and Topology on IoT Intrusion Detection Model Generalizability

Amin Kaveh, Christian Rohner, Andreas Johnsson · 2024

Intrusion Detection Systems (IDS) play a critical role in safeguarding loT networks, especially in sectors like healthcare, manufacturing, and smart cities where safety is paramount. Machine learning (ML) holds significant promise for training IDS models, leveraging data from past attacks. However, the effectiveness of these models are dependent on the quality and diversity of training data, which is often limited from the perspective of a single network operator. This paper delves into the challenges of ML-based IDS model generalization across loT network scenarios with expected distributional shifts in the data. We examine variations in known attack patterns and changes in loT network configurations, quantifying their impact on model generalizability. These shifts originates from when multiple network operators seek to share knowledge to enhance their respective IDS capabilities, when a new attack variation is launched, or when an operator reconfigure its network. We explore two approaches to address these chal-lenges: namely data sharing and horizontal federated learning for privacy preservation. While data sharing proves effective across scenarios, it relies on mutual trust among network operators. In contrast, federated learning preserves privacy but is less effective, especially when the network topology is the primary driver of distributional shifts in the train and test data. To facilitate our study, we implemented Blackhole attack variation strategies within the Cooja network simulator. Our objective was to generate a large dataset enabling comprehensive analysis of attack variations across diverse set of network configurations to study the impact on ML-based IDS for loT networks.

Read the paper · More papers on PaperTik