Detecting Malicious Network Activities: Machine Learning-Based ARP Poisoning Detection on RT-IoT2022 Dataset

Anshika Sharma, Himanshi Babbar · 2024

This makes it possible to detect Address Resolution Protocol (ARP) poisoning attempts, which is essential for preserving network communications’ security and integrity, especially in the context of Internet of Things (IoT) deployments. Using the RT-IoT2022 dataset, which offers a thorough representation of network technology in IoT settings, a novel method in this paper has been demonstrated for recognising ARP poisoning attacks using machine learning (ML) techniques. Its ability to create reliable models for identifying malevolent ARP poisoning behaviour is made possible by the dataset’s extensive collection of network activity, including ARP traffic, device connections, and interaction patterns. Through the use of supervised learning methods like Extreme Gradient Boosting (XGBoost), Random Forests (RF), Decision Trees (DT), and Support Vector Machines, the goal is to train classifiers that can accurately distinguish between unusual ARP poisoning activity and normal ARP traffic. It also examines how well feature engineering and selection methods work to improve the models’ performance. The effectiveness of the method has been evaluated for identifying ARP poisoning threats and its potential for practical use in IoT security applications through comprehensive testing and analysis. The results highlight the significance of utilising ML to improve cybersecurity in IoT environments and advance anomaly detection techniques in IoT networks. The finding demonstrates that the XGBoost is the most accurate method, with an accuracy percentage of $\mathbf{9 9. 7 6 \%}$. On the other hand, the rates for AdaBoost, DT, and RF are $\mathbf{9 3. 3 4 \%}, \mathbf{9 5. 2 1 \%}$ and $\mathbf{9 8. 9 9 \%}$ respectively.

Read the paper · More papers on PaperTik