AURA: Adaptive Unified Real-Time Analytics for IoT Intrusion Detection

Sanket Mishra, V. Aravindan, Rajkanwar Singh, Vikash Kumar Singh · 2024

In high-volume, high-velocity contexts, threat identification requires effective real-time data stream analysis. This study offers a novel architecture—real-time processing of high-speed data streams—that is critical for effective threat identification in dynamic contexts. By using a publish-subscribe approach with Apache Kafka, the system is able to manage differences in data volume between many nodes. Experiments on the CICIoV24 and the CICEVSE2024 datasets indicate that the XGBoost model performs better, with high accuracy and robustness against adversarial attacks. Its performance degrades during the HopSkipJump attack, however, defence training can help with it. Moreover, our analysis shows that RandomForest and ExtraTrees perform better in noisy data from the CICIoV24 and XGBoost perform better in noisy data from the CICEVSE24 dataset, emphasizing the importance of selecting algorithms based on performance indicators. The architecture utilizes PyFlink’s distributed computation framework to improve computational efficiency for real-time processing and solves idea drift to ensure flexibility in changing data attributes.

Read the paper · More papers on PaperTik