Bringing IoT Intrusion Detection to the Edge

Barikisu A. Asulba, Pedro F. Souto, Lúıs Almeida · 2024

Real-time network intrusion detection systems (NIDS) are essential for securing IoT networks.To enhance real-time detection, NIDS have to be deployed in the networks they protect, e.g., home networks or industrial networks, typically in edge equipment that has limited resources, e.g. the network router.Recent developments have shown the potential of using Machine Learning (ML), particularly Deep-Learning (DL) algorithms.However, DL is rather costly in computing resources.We present a novel approach based on classical ML methods suitable for anomaly detection (one-class methods), that shows a comparable detection capability with a fraction of the computing resource requirements of DL.We use the EDGE IoT/IIoT dataset to train five one-class ML algorithms.These include (SGD) One-Class Support Vector Machine, Elliptic Envelope, Isolation Forest, and Local Outlier Factor, each trained with different set sizes.We implement the models with Python for its wide dissemination and support, and we characterize the detection performance, the execution time and used memory in a setup based on a RaspberryPi that we consider representative of edge equipment.Our findings show that OCSVM generally outperforms the other approaches, including a DL model -MSM AE, in all metrics showing suitability for execution in the edge.

Read the paper · More papers on PaperTik