Adaptive Real-Time Malware Detection for IoT Traffic Streams: A Comparative Study of Concept Drift Detection Techniques

D Bharani, V. Priya, S. Saravanan · 2024

As IoT expands dynamically, cybersecurity threats are evolving with time; thus, classical malware detection systems are no more appropriate, due to the phenomenon of concept drift and the necessity of handling large amount of data while detecting malware. Concept drift is used to refer to the statistical properties of malware that change over time as the malware behavior changes. We henceforth propose a real-time system to detect malware within a large-scale network traffic streams in the presence of concept drift. The system is capable of processing continuous large volumes of IoT traffic in real-time as it is implemented using Apache Spark and Apache Kafka. The proposed system also compares the performance of six different concept drift detection techniques: KS test, CUSUM, ADWIN, KSWIN, DDM, Page Hinkley on NSL-KDD and IoT -23 datasets. The comparison results show that KS test correctly identified concept drift in both the datasets. The proposed system makes an IoT environment with better malware detection capabilities by integrating the adaptive mechanism in real-time data processing tools apart from achieving high performance and scalability.

Read the paper · More papers on PaperTik