Developing Deep Learning Models to Predict Benign and Malicious Attacks in IoT Networks

Nik Muhammad Danial Bin Nik Ram Zaedi, Amy Lim Hui Lan, Goh Hui-Ngo · 2024

The Internet of Things (IoT) has afforded increased connectivity across various domains which increased cybersecurity vulnerabilities. Threats like Distributed Denial of Service (DDoS) attacks, Spoofing, and web-based attacks pose a significant danger to IoT networks, which require more advanced Network Intrusion Detection Systems (NIDS) to effectively counter these threats. The aim of this paper is to investigate the viability of DL-based classifiers for NIDS. The CICIoT2023 dataset is used in this study. Feature reduction is performed using the Pearson’s Correlation Coefficient (PCC) Matrix and features that contain all-zero values are removed. To resolve the class imbalanced issue, Synthetic Minority Oversampling (SMOTE) is applied exclusively on the training set only. For comprehensive comparison studies, a total of nine classifiers have been considered which can be categorized into machine learning (ML)-based classifiers and Deep Learning (DL)-based classifiers. MLbased classifiers consist of Random Forest (RF), Naive Bayes (NB), Decision Tree (DT), K-Nearest Neighbors (KNN) and Logistic Regression (LR), and while DL-based classifiers consist of Long Short-Term Memory (LSTM), Bidirectional Long-Short Term Memory (BiLSTM), 1-dimensional convolutional neural network (1D-CNN) and recurrent neural network (RNN). The findings revealed that the DL-based classifiers have consistently recorded high accuracy, precision, recall, F1 score and AUC of more than 0.9. Although ML-based classifiers have recorded high precision and AUC, the accuracy, recall and F1 score have a wider variation in scores. The consistency and high scores across various evaluation metrics indicate the viability of adopting DL-based classifiers for building NIDS.

Read the paper · More papers on PaperTik